Hackers are using EternalBlue vulnerability discovered by NSA and an exploit released by Shadow Brokers to infect unpatched Windows computers with WannaCry
A new strain of ransomware has spread quickly all over the world, causing crisis in National Health Service hospitals and facilities around England …
Context & Ripple Effects
The Shadow Brokers' release of an NSA-built exploit has now produced its first global casualty: WannaCry is encrypting unpatched Windows machines at scale, and England's National Health Service is the most visible victim, with hospitals diverting patients as systems go down. Attribution reporting soon after pointed at North Korea's Lazarus group, per sources linking the NSA and Britain's National Cyber Security Centre.
What makes this story bigger than one outbreak is what researchers found next: EternalBlue had already been quietly used in a possibly larger Adylkuzz cryptocurrency-mining campaign before WannaCry, and within weeks a Petya variant was pairing password theft with the same exploit. The leak turned a stockpiled NSA capability into shared attacker infrastructure.
First-order effects
- NHS hospitals and facilities across England are forced onto manual operations — cancellations and patient diversions — while IT teams worldwide race to patch unpatched Windows machines still exposed to EternalBlue.
Second-order effects
- Every ransomware crew gains a proven wormable delivery mechanism: within weeks Eset and Recorded Future identify a Petya variant reusing EternalBlue, and by the following year Wired reports the leaked exploit has become a go-to hacker tool precisely because so many machines remain unpatched.
Third-order effects
- The pattern extends beyond ransomware into outright paralysis of public institutions — by 2019 EternalBlue attacks are taking down American cities including Allentown, San Antonio, and Baltimore — pushing the structural question of whether intelligence agencies should disclose exploitable flaws or hoard them, since every hoarded bug is a latent weapon against the agencies' own constituents.
The trend: Leaked state-grade exploits are collapsing the gap between nation-state tooling and commodity cybercrime, turning single vulnerabilities into years-long waves of ransomware, cryptomining, and municipal shutdowns.