About Us | Contact Us
View Cart

Many School Districts Are Still Vulnerable To WannaCry

By Vigilize | Tuesday, May 28, 2019 - Leave a Comment

Years after patches were released, many systems remain vulnerable…


An article review.


While it has been over two years since the WannaCry exploit was publicly announced, a new report submitted by our own Sean Waugh says that hundreds of thousands of internet-connected machines are still vulnerable…and many of those machines belong to government agencies and other public institutions.

The investigation began when website Ars Technica began looking into a recent ransomware attack that disabled many Baltimore city government agency systems earlier this month. While working on a follow-up to that story, reporters discovered eight additional servers on the Baltimore County School District’s network that were vulnerable to the WannaCry exploit more than two years after patches became available.

When it comes to missing patches, Baltimore County isn’t alone: open internet scans have uncovered hundreds of thousands of vulnerable machines, with a disproportionate number of those belonging to schools and other government agencies. This news highlights an ongoing problem as IT departments in public agencies often deal with a lack of funding and support, often leading to vulnerabilities such as WannaCry remaining unpatched. A lack of funding can also mean older devices that require outdated, vulnerable protocols must remain in service, making mitigation more difficult.

The tools used by the reporters to find these vulnerabilities are available to the public, so it is a safe bet that criminals are also aware of them. While schools and other public institutions are far from the only vulnerable organizations, they are often targeted preferentially by criminals due to the increased likelihood that the ransom will be paid. If this wasn’t bad enough, a new round of serious vulnerabilities in Intel CPUs was announced recently, requiring another set of patches.


Original article by Sean Gallagher writing for Ars Technica.


same_strip_012513


 

Latest News
     A Timeline Update as of 02/22/21 An update to our Newest Employee’s FIRST Technical Article Another interim post-mortem review . . . . A Note About Updates: We have decided to leave the original article as it was originally posted and to update this post with any changes that have been made. You can see […]
    Another awareness poster for YOUR customers (and users).  Now that we have our own employees aware, maybe it’s time to start posting content for our customers! Download the large versions here: Awareness Poster (Portrait) Awareness Poster (Landscape)   You are welcome to print out and distribute this around your office.  
    A Webinar-Movie The 2020 annual webinar update on the subject will include a review of the previous years’ movies that are already available, and a discussion about alternative tactics that have arisen from recent virtual conferences and regulator panels.
    The cybersecurity industry faces challenges, and some of them may involve your business… An article review. In a world where threats to your organization’s electronic assets are constantly emerging and evolving a cybersecurity insurance policy can help mitigate risk…but what kind of risk does the cybersecurity insurance industry face?  A new article in the Harvard […]
    What are the top seven risks your board should know about in 2021? Since his first board presentation in 2000, when Dan presents audit reports to boards of directors, he also talks to the board about the top risks the institution is facing. Since 2006, Dan has been compiling a list of the “top seven […]
    A Timeline as of 01/24/2021 Our Newest Employee’s FIRST Technical Article Another interim post-mortem review . . . . A Note About Updates: We are leaving this article as is, but for any updates to the timeline, check the Autopsy of the SolarWinds Hack Timeline Update article!      – Vigilize Introduction: As the managing […]
    PRESS RELEASE – FOR IMMEDIATE RELEASE BUSINESS NEWS FORUM AND CONFERENCE NEWS infotex is proud to announce that Dan Hadaway will be moderating a series of IT Forums for the Ohio Bankers League. “We are excited to continue fostering the relationship with the OBL to help educate and keep Risk Management at the forefront of […]
    Top 7 Trend Articles of 2021. . .  . . .For ISOs of Small Financial Institutions. Welcome to our annual T7 article:  a list of our favorite trend articles from the past year.  Our intent: help you organize your thoughts as your work through your strategic planning process.  We hope reviewing these articles will help you […]
    Another awareness poster for YOUR customers (and users).  Now that we have our own employees aware, maybe it’s time to start posting content for our customers! Download the large versions here: Awareness Poster (Portrait) Awareness Poster (Landscape)   You are welcome to print out and distribute this around your office.  
    A Webinar-Movie In our current world of uncertainty there is at least one thing that is certain. Business needs to continue, and that means that it is important for managers to be able to meet with their team even if everyone is working remotely at this point. In this Webinar-Movie, Dan will compare virtual meeting […]