Experts say ransomware victims like Baltimore have not taken sufficient measures to protect against the EternalBlue exploit two years after it first leaked
Nominations are now open for 2019 Rising Star Awards. Dave Aitel / CyberSecPolitics : Baltimore is not EternalBlue Daniel Uria / UPI : Baltimore seeks answers, help for crippling cyberattack linked to NSA Robert Graham / Errata Security : A lesson in journalism vs. cybersecurity Tweets: Cyber Baba Yaga / @dave_maynor : I've answered this question privately it's time to address it publicly: why do I have such a problem with @nicoleperlroth story? I was alerted to it by a private group of CIOs with take away was “we are doing the right thing and if hit by military grade cyber...we are good” Robᵇᵉᵗᵒ Graham / @erratarob : Eternalblue was released over two years ago.. If an organization has substantial numbers of Windows machines that have gone 2 years without patches, then that's squarely the fault of the organization, not Eternalblue. Robert M. Lee / @robertmlee : It's an odd discussion and I don't know it's fully fleshed out but I do think over time the culpability changes. 2 years after patches are available I'm more inclined to blame the actual adversary using the exploits. Thomas Rid / @ridt : Three days ago The New York Times claimed a variant of a ransomware used against city governments, including Baltimore—known as RobbinHood—was re-using EternalBlue, an old, leaked NSA exploit. Proving that link forensically should be straightforward. So far no proof. Beau Woods / @beauwoods : Two years after #WannaCry, and #NotPetya, this thread is more true. Focus on a specific exploit is short sighted. Adversaries understand this and adopt new exploit modules to stay ahead of defenders. Why is @nytimes still writing the same story today? https://twitter.com/... Robert M. Lee / @robertmlee : This is a good example of what a bad take looks like on this situation. Analogies to things like cars is highly misleading in security. Also I blame the adversary not the victim but also not the NSA two years after patches were released https://twitter.com/... Nicole Perlroth / @nicoleperlroth : A couple points on Dave's hit piece that our story was a “badly researched” and written to sell books: 1. There are multiple IR teams on the ground in Baltimore. Every single one has confirmed the presence of EternalBlue as a propagation tool. 1/X) Every. Single. One. https://twitter.com/... Thomas Rid / @ridt : Two noteworthy reactions to the NYT's EternalBlue claim with good overviews:@daveaitelhttps://t.co/ xNEb8yjZdi@ErrataRob https://blog.erratasec.com/... Also, https://twitter.com/... @erratarob : This is fake news. The story is crafted to place all the blame on Eternalblue, when it's almost incidental. Just because all ransomware these days contain Eternalblue doesn't mean Eternalblue is responsible for all ransomware. https://twitter.com/...