NotPetya (June 2017): How a Tax Software Update Wiped Out Global Networks
On June 27, 2017, a malware outbreak later called NotPetya began in Ukraine and spread to multinational companies within hours. Shipping giant Maersk had to...
On June 27, 2017, a malware outbreak later called NotPetya began in Ukraine and spread to multinational companies within hours. Shipping giant Maersk had to...
NotPetya spread by stealing administrator credentials from memory and reusing them across the network. Tiering your Active Directory admin accounts stops...
NotPetya combined credential theft with legitimate admin tools to move across networks. Detecting that pattern early is one of the most effective ways to...
The short version: NotPetya, in 2017, entered companies through a trusted software update and then spread using administrator passwords stolen from one...
On May 12, 2017, WannaCry ransomware spread across the world in a matter of hours, encrypting files on hundreds of thousands of Windows computers in more...
SMBv1 is a decades-old file-sharing protocol with known critical flaws, and it was the doorway for WannaCry and NotPetya. Here is how to remove it from...
WannaCry and its successors exploited SMB flaws to spread across networks. Even with SMBv1 removed, detecting suspicious SMB activity is a valuable early...
The short version: In 2017, WannaCry ransomware infected hundreds of thousands of computers worldwide using a Windows flaw that had been patched two months...