3 ms·
It's not surprising that the system was using an unpatched OS. Many of these tools are not connected to the external internet, and they are qualified using the
by PhaseLockk 8y ago
It's not surprising that the system was using an unpatched OS. Many of these tools are not connected to the external internet, and they are qualified using the exact version of the software that is installed during delivery. I don't really know the details of foundry operations, but it seems like there are more incentives against installing windows updates than for it. Looking at your article it seems to say the same thing:
> patching is not always an easy endeavor in manufacturing environments because any code changes must be rigorously tested to ensure they don't have a real-world impact - for example on industrial control systems or supervisory control and data acquisition systems, which control the software and hardware that runs manufacturing processes. Indeed, ICS and SCADA systems may have a lifespan of 20 to 30 years. Many were never designed to be internet connected.
- AnIdiotOnTheNet 8y agoSince this is ransomware, it's unclear how an OS patch would have helped anyway.
- mh8h 8y agoThe ransomeware in this case spreads by exploiting a vulnerability that is now patched in Windows.
- zenexer 8y agoAdditionally, if the machines were connected to the internet, the killswitch would've prevented it from spreading. WannaCry doesn't spread if a particular hostname resolves; this acts as a killswitch. Marcus Hutchins purchased the relevant domain name after reverse engineering WannaCry and noticing the killswitch. Edit: That's not to say the machines should be connected to the internet; I'm just explaining the circumstances that allowed this to occur.