About Us | Contact Us
View Cart

Many School Districts Are Still Vulnerable To WannaCry

By Vigilize | Tuesday, May 28, 2019 - Leave a Comment

Years after patches were released, many systems remain vulnerable…


An article review.


While it has been over two years since the WannaCry exploit was publicly announced, a new report submitted by our own Sean Waugh says that hundreds of thousands of internet-connected machines are still vulnerable…and many of those machines belong to government agencies and other public institutions.

The investigation began when website Ars Technica began looking into a recent ransomware attack that disabled many Baltimore city government agency systems earlier this month. While working on a follow-up to that story, reporters discovered eight additional servers on the Baltimore County School District’s network that were vulnerable to the WannaCry exploit more than two years after patches became available.

When it comes to missing patches, Baltimore County isn’t alone: open internet scans have uncovered hundreds of thousands of vulnerable machines, with a disproportionate number of those belonging to schools and other government agencies. This news highlights an ongoing problem as IT departments in public agencies often deal with a lack of funding and support, often leading to vulnerabilities such as WannaCry remaining unpatched. A lack of funding can also mean older devices that require outdated, vulnerable protocols must remain in service, making mitigation more difficult.

The tools used by the reporters to find these vulnerabilities are available to the public, so it is a safe bet that criminals are also aware of them. While schools and other public institutions are far from the only vulnerable organizations, they are often targeted preferentially by criminals due to the increased likelihood that the ransom will be paid. If this wasn’t bad enough, a new round of serious vulnerabilities in Intel CPUs was announced recently, requiring another set of patches.


Original article by Sean Gallagher writing for Ars Technica.


same_strip_012513


 

Latest News
    You’ve heard it from every MSSP you’ve met: the definition of a SIEM is in the eye of the beholder. But at infotex, we are not talking about the database – an asset whose definition is continuously evolving. We’re talking about the way three teams collaborate in an overall Technology Risk Monitoring process. And whether […]
    A new study shows organizations are responding to cyber attacks faster than ever, so why is that bad news? An article review. When it comes to cyber attacks, the sooner an organization can begin to respond to an attack the better, so the results of a new study showing a drop in the amount of […]
    …a Crash Course of Security Measures The first article by Sara Fultz, Creative Assistant of infotex! Introduction: As the managing partner of infotex, I am proud to introduce the “debut article” for Sara Fultz.  I told Sara “write an article showing us what you’ve learned that the technical staff will appreciate.” As I read her […]
    infotex Programming Coordinator, Michael Hartke, introduces a high level overview of the upcoming update to the infotex SIEM. Look for more movies in the coming months informing our Clients, and those just now learning about us, about the SIEM and its features and functions.
    Another awareness poster for YOUR customers (and users).  Now that we have our own employees aware, maybe it’s time to start posting content for our customers! Download the large versions here: Awareness Poster (Portrait) Awareness Poster (Landscape)   You are welcome to print out and distribute this around your office.  
    As the investigation of the SolarWinds Hack was ongoing, another hack stole some of the limelight… This is the final update on the SolarWinds hack unless a major development comes to light. You can see the previous article here: “Autopsy of the SolarWinds Hack Update“. One of the largest cyber-espionage campaigns in the history of […]
    Employees working from home may find it more difficult to follow security policies… An article review. The surge in employees working from home during the pandemic created many headaches for IT departments around the world, many of whom had no telecommuting policies or procedures before the start… but what about the employees who had to […]
    A Webinar-Movie infotex presents the 2021 update of a previously released webinar presented by our Lead Non-Technical Auditor, Adam Reynolds. This movie-short is intended for those who are planning to participate in an infotex Incident Response Test. Not sure about the importance of an Incident Response Test? Check out onetest.infotex.com for more information! Please let […]
    PRESS RELEASE – FOR IMMEDIATE RELEASE BUSINESS NEWS INFOTEX PROMOTES BRYAN BONNELL TO DIGITAL MEDIA MANAGER infotex, the Managed Security Service Provider, announced Bryan Bonnell’s promotion from Senior Data Security Analyst to Digital Media Manager.  “He will continue his normal DSA duties on a limited basis, because we want everybody to stay in touch with […]
    PRESS RELEASE – FOR IMMEDIATE RELEASE BUSINESS NEWS RYAN HENSLER OF INFOTEX, EARNS CISSP CERTIFICATE Ryan Hensler, Senior NOC Associate of infotex, Inc., recently received the CISSP certification. “Ryan has proven himself to be a seasoned security professional both in his work for infotex and now through achieving this certification.” said Sean Waugh, Information Security Officer. […]