Company News: Page (1) of 1 - 05/18/17 Email this story to a friend. email article Print this page (Article printing at MyDmn.com).print page facebook

Paladion Releases a Public Cyber Advisory

(May 18, 2017)
DMN Newswire--2017-5-18--
Paladion - a global cyber defence company announced today that since Sunday, May 14, 2017, it has discovered new variants of the WannaCry Ransomworm. These new variants have no connection to the previous Kill Switch found in the original ransomware, which started wreaking havoc across the globe on May 12, 2017.

Speaking about the latest global cyber attack, Amit Roy, executive vice president and regional head for EMEA at Paladion, said, 'The first large wave of WannaCry may have died down because a domain the ransomware was calling was registered by a security researcher, thus revealing a kill switch. However, the fact remains that if affected devices are not patched immediately and mitigation steps are not taken, there is still a high possibility of re-infection.' 



The WannaCry ransomware was created in such a way that before every infection it would try to call the domain iuqerfsodp9ifjaposdfjhgosurijfaewrwergwea.com. If there wasn't a response, it would lock the victim's machines. However, if the domain was up and running, the malware would stop in its tracks ' slowing down the spread. 

'Since Sunday, we have discovered WannaCry Ransomworm versions without a connection to the previous Kill Switch. Of the variants that surfaced on 14th May 2017, two have an updated domain name or kill switch and one does not have a kill switch. However, the variant with no kill switch has bugs that are preventing it from encrypting user data. But then, the propagation part via ETERNALBLUE and DOUBLEPULSAR works without a hitch,' explained Roy. 

In order to contain the spread of the cyber attack and to mitigate, Paladion advices that MS17-010 and related patches for CVE-2017-0143 to CVE-2017-0148 should be patched immediately. 

Also important is the Shadow Brokers leak of exploit tools that became public in April 2017. The dump includes several other CVEs, and these patches should be prioritized to stay protected from imminent threats. The patches are listed against each exploit below: 

Exploit Name

Solution

EternalBlue


Page: 1


Related Keywords:Amit Roy, WannaCry, ransomware, paladion
Related Sites: DMN Newswire ,   itbusinessnet.com ,   VideoBasedTutorials
Related Newsletter: Tutorial Finder ,   Review Seeker ,   IBN - IT Weekly Newsletter ,   DMN Newswire Newsletter
HOT THREADS on DMN Forums

Our Privacy Policy --- @ Copyright, 2015 Digital Media Online, All Rights Reserved