4 ms·
>> against unpatched Windows 7 systems >> Since data integrity and confidential information haven’t been compromised, the company believes the attack wasn’t th
by Rotdhizon 8y ago
>> against unpatched Windows 7 systems
>> Since data integrity and confidential information haven’t been compromised, the company believes the attack wasn’t the work of a hacker
>> According to CEO C.C. Wei, the attack is purely due to the company’s own negligence. Wei also said that he doesn’t think there is any hacking behavior involved.
Those three lines sum up the article.
From a different article, the virus got onto their network when they installed some type of new software/tool. They didn't check it before they deployed it, turns out it had wannacry on it. Since the networks this virus infected weren't internet connected, it didn't hit the kill-switch domain. So it was left to run wild until they contained it.
https://www.databreachtoday.com/wannacry-outbreak-hits-chipmaker-could-cost-170-million-a-11285 https://www.databreachtoday.com/wannacry-outbreak-hits-chipm...
- PhaseLockk 8y agoIt's not surprising that the system was using an unpatched OS. Many of these tools are not connected to the external internet, and they are qualified using the exact version of the software that is installed during delivery. I don't really know the details of foundry operations, but it seems like there are more incentives against installing windows updates than for it. Looking at your article it seems to say the same thing: > patching is not always an easy endeavor in manufacturing environments because any code changes must be rigorously tested to ensure they don't have a real-world impact - for example on industrial control systems or supervisory control and data acquisition systems, which control the software and hardware that runs manufacturing processes. Indeed, ICS and SCADA systems may have a lifespan of 20 to 30 years. Many were never designed to be internet connected.
- AnIdiotOnTheNet 8y agoSince this is ransomware, it's unclear how an OS patch would have helped anyway.
- mh8h 8y agoThe ransomeware in this case spreads by exploiting a vulnerability that is now patched in Windows.
- zenexer 8y agoAdditionally, if the machines were connected to the internet, the killswitch would've prevented it from spreading. WannaCry doesn't spread if a particular hostname resolves; this acts as a killswitch. Marcus Hutchins purchased the relevant domain name after reverse engineering WannaCry and noticing the killswitch. Edit: That's not to say the machines should be connected to the internet; I'm just explaining the circumstances that allowed this to occur.