17/05/2017
www.auxtaa.com has brought few things for your reference:
https://goo.gl/W2ZvxC
• If you are using Win Vista, 7, 8.1 & 10: In March, Microsoft released a security update which addresses the vulnerability that these attacks are exploiting. Those who have Windows Security Update enabled are protected against attacks on this vulnerability.
For those organizations who have not yet applied the security update, we suggest you immediately deploy Microsoft Security Bulletin MS17-010.
• Activate Windows Defender: For customers using Windows Defender, Microsoft released an update earlier today which detects this threat as Ransom:Win32/WannaCrypt. As an additional “defense-in-depth” measure, keep up-to-date anti-malware software installed on your machines. Customers running anti-malware software from any number of security companies can confirm with their provider whether they are protected.
• If using older version of Windows: Customers running versions of Windows that no longer receive mainstream support may not have received the above mentioned Security Update released in March. Given the potential impact to customers and their businesses, Microsoft has released a Security Update for platforms in custom support only. Windows XP, Windows 8 and Windows Server 2003 Security Updates are broadly available for download now (see links below).
• Additional Steps to consider: This attack type may evolve over time, so any additional defense-in-depth strategies will provide additional protections. (For example, to further protect againstSMBv1 attacks, customers should consider blocking legacy protocols on their networks). Some of the observed attacks use common phishing tactics including malicious attachments. Customers should use vigilance when opening documents from untrusted or unknown sources.
More information on the malware is available from the Microsoft Malware Protection Center though the Windows Security blog. www.auxtaa.com is working continuously to provide additional assistance as the situation evolves, and will update this blog with details as appropriate.
Security Advisory - DOs & DONTs | www.auxtaa.com Ransomware is a very tricky malware which infects a computer when a user opens a phishing email.