/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Hackers are using EternalBlue vulnerability discovered by NSA and an exploit released by Shadow Brokers to infect unpatched Windows computers with WannaCry

A new strain of ransomware has spread quickly all over the world, causing crisis in National Health Service hospitals and facilities around England

Wired Lily Hay Newman

Context & Ripple Effects

WannaCry is the first mass deployment of EternalBlue, an NSA-built Windows exploit that the Shadow Brokers leak put into any hacker's hands. Within days it had crippled National Health Service hospitals across England, forcing cancelled procedures and diverted ambulances.

The blast radius kept growing after this story: researchers found EternalBlue had already powered a quieter, possibly larger crypto-mining campaign (Adylkuzz), Eset and Recorded Future flagged a Petya variant reusing the same exploit weeks later, and by 2018 Wired called the leaked tool a go-to for hackers because so many machines stayed unpatched.

First-order effects

  • Unpatched Windows users — most visibly NHS hospitals in England — face immediate encryption of files and disrupted care, with no fix available until machines are patched or taken offline.
  • Attribution pressure lands on North Korea: NSA and Britain's National Cyber Security Centre later linked the attack to the Lazarus hacking group, turning a criminal incident into a state-actor case.

Second-order effects

  • EternalBlue stops being a one-off weapon and becomes commodity infrastructure — copycat campaigns like the Petya variant fold the same exploit into new ransomware that also harvests passwords from infected systems.
  • Organizations that skipped patching become repeat targets: two years on, the same leaked exploit is paralyzing American city governments including Allentown, San Antonio, and Baltimore.

Third-order effects

  • The leak establishes a lasting pattern: once a stockpiled government exploit escapes, it outlives its original owner and shifts the burden of defense onto every unpatched machine worldwide.
  • Sustained exploitation of a single leaked vulnerability pushes patching discipline and disclosure policy toward the center of national security debates, since civilian infrastructure — hospitals, then city networks — absorbs the cost of intelligence-agency tooling.

The trend: Leaked nation-state exploits are becoming durable criminal infrastructure, with each unpatched population converting a single intelligence-agency tool into years of ransomware campaigns.