Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Comments
WannaCry Remains No. 1 Ransomware Weapon
Newest First  |  Oldest First  |  Threaded View
<<   <   Page 2 / 2
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
8/29/2019 | 1:29:02 PM
WannaCry

The main lesson is to keep the systems up to date, obvisuly. 

 

tdsan
50%
50%
tdsan,
User Rank: Ninja
8/28/2019 | 6:48:52 PM
Re: The most effective defense?
Andrew, I must agree with you, there is no excuse.

Companies are still holding on to Windows 7 (wow), this is what it means to be loyal to a fault or not have the personnel on staff to make this migration happen (holding on to the very end).

After January 14, 2020, Microsoft will no longer provide security updates or support for PCs running Windows 7

I do think there are solutions to this problem, roll-out VDI solution and deploy desktops in a virtual session, this can be easily done without breaking the bank. VMware HorizonView or Citrix XenDesktop/XenApp work, if they want to go to the cloud, use WorkSpaces, there are a number of things they could have done.

At the end of the day, it is time to move off this platform, this says a lot about companies not taking into consideration the time and planning stages they could have planned to create a seamless migration process. When companies are hacked, the business owners, executive staff members should be removed from their position because they did not follow best practices and follow due-diligence.

Windows 7 End of Life

T
AndrewfOP
50%
50%
AndrewfOP,
User Rank: Moderator
8/28/2019 | 9:20:57 AM
Re: The most effective defense?
"All good points. But when their apps or processes still rely on antiquated OSes like Win7 and updating disrupts the biz, then some orgs just ride it out with security tools to catch these threats, etc."

While I sympathize with the familiarities of existing business tools on machines with old Window systems and the disruptions caused on replacing them, it's still no excuse not to plan for the future with new tools fitting business needs that would be compatible with the latest OS. Especially now that Microsoft seems to be getting out of making-new-Windows-to-make-money business, future disruptions to business should be minimal and all the more reason to get new tools with security features built in.

 
REISEN1955
50%
50%
REISEN1955,
User Rank: Ninja
8/27/2019 | 2:54:38 PM
Re: The most effective defense?
True and the OS update issue is the responsibility of the IT staff and team to make clear and evident - THAT is their job and all too often, well, disrupting the business is just TOO HARD.  Like that patch that brought down Equifax.  Right?   I work with a CSirt team using great tools and while every firm and small business may not have access, it still has to be tackled as best allowed.  But keeping old W7 systems running now is asking for trouble.  As it was with XP ( of which alot of that is still out there on legacy boxes).  The IT staff has a daunting job sometimes but it is THEIR JOB and if they do not like it, there are always trade school courses on welding. 

Disclaimer: I am something of an expert on disaster recovery techniques when 18 years ago I had to walk down out of my office building in lower Manhattan and shortly later the data center on the 103rd floor of the south tower followed me down.  I am a survivor of that day from Aon, on the 101st floor, S-tower, of the World Trade Center.
Kelly Jackson Higgins
50%
50%
Kelly Jackson Higgins,
User Rank: Strategist
8/27/2019 | 2:33:48 PM
Re: The most effective defense?
All good points. But when their apps or processes still rely on antiquated OSes like Win7 and updating disrupts the biz, then some orgs just ride it out with security tools to catch these threats, etc.
REISEN1955
50%
50%
REISEN1955,
User Rank: Ninja
8/27/2019 | 2:30:45 PM
The most effective defense?
An educated user pool to start with with basic rules of email iusage.  Secondly a verified, vetted and tested  backup and restoration plan --- make sure it works.  Third are active patching and firewall monitoring.  All fall under the care of the internal IT staff and if they do not do these chores ..... well, Welcome to Hell.  
<<   <   Page 2 / 2


Mobile Banking Malware Up 50% in First Half of 2019
Kelly Sheridan, Staff Editor, Dark Reading,  1/17/2020
7 Tips for Infosec Pros Considering A Lateral Career Move
Kelly Sheridan, Staff Editor, Dark Reading,  1/21/2020
For Mismanaged SOCs, The Price Is Not Right
Kelly Sheridan, Staff Editor, Dark Reading,  1/22/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment:   It's a PEN test of our cloud security.
Current Issue
IT 2020: A Look Ahead
Are you ready for the critical changes that will occur in 2020? We've compiled editor insights from the best of our network (Dark Reading, Data Center Knowledge, InformationWeek, ITPro Today and Network Computing) to deliver to you a look at the trends, technologies, and threats that are emerging in the coming year. Download it today!
Flash Poll
How Enterprises are Attacking the Cybersecurity Problem
How Enterprises are Attacking the Cybersecurity Problem
Organizations have invested in a sweeping array of security technologies to address challenges associated with the growing number of cybersecurity attacks. However, the complexity involved in managing these technologies is emerging as a major problem. Read this report to find out what your peers biggest security challenges are and the technologies they are using to address them.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-7245
PUBLISHED: 2020-01-23
Incorrect username validation in the registration processes of CTFd through 2.2.2 allows a remote attacker to take over an arbitrary account after initiating a password reset. This is related to register() and reset_password() in auth.py. To exploit the vulnerability, one must register with a userna...
CVE-2019-14885
PUBLISHED: 2020-01-23
A flaw was found in the JBoss EAP Vault system in all versions before 7.2.6.GA. Confidential information of the system property's security attribute value is revealed in the JBoss EAP log file when executing a JBoss CLI 'reload' command. This flaw can lead to the exposure of confidential information...
CVE-2019-17570
PUBLISHED: 2020-01-23
An untrusted deserialization was found in the org.apache.xmlrpc.parser.XmlRpcResponseParser:addResult method of Apache XML-RPC (aka ws-xmlrpc) library. A malicious XML-RPC server could target a XML-RPC client causing it to execute arbitrary code. Apache XML-RPC is no longer maintained and this issue...
CVE-2020-6007
PUBLISHED: 2020-01-23
Philips Hue Bridge model 2.X prior to and including version 1935144020 contains a Heap-based Buffer Overflow when handling a long ZCL string during the commissioning phase, resulting in a remote code execution.
CVE-2012-4606
PUBLISHED: 2020-01-23
Citrix XenServer 4.1, 6.0, 5.6 SP2, 5.6 Feature Pack 1, 5.6 Common Criteria, 5.6, 5.5, 5.0, and 5.0 Update 3 contains a Local Privilege Escalation Vulnerability which could allow local users with access to a guest operating system to gain elevated privileges.