WannaCry (May 2017): SMBv1, Unpatched Servers and What Cloud Teams Missed
On May 12, 2017, WannaCry ransomware spread across the world in a matter of hours, encrypting files on hundreds of thousands of Windows computers in more...
Insights
Articles in Retrospectives.
On May 12, 2017, WannaCry ransomware spread across the world in a matter of hours, encrypting files on hundreds of thousands of Windows computers in more...
SMBv1 is a decades-old file-sharing protocol with known critical flaws, and it was the doorway for WannaCry and NotPetya. Here is how to remove it from...
WannaCry and its successors exploited SMB flaws to spread across networks. Even with SMBv1 removed, detecting suspicious SMB activity is a valuable early...
The short version: In 2017, WannaCry ransomware infected hundreds of thousands of computers worldwide using a Windows flaw that had been patched two months...
In February 2017, Google Project Zero researcher Tavis Ormandy noticed something strange in search results: fragments of private data from websites that...
When a provider you depend on — a CDN, identity platform, CI/CD service or SaaS tool — announces that tokens or secrets may have leaked, speed matters more...
When a provider leaks session tokens, the question is whether anyone used them. Detection focuses on sessions that look valid but behave differently from...
The short version: In 2017, a bug at Cloudflare, a major internet provider, leaked private data from customer websites, including login sessions. The...
On February 28, 2017, Amazon S3 in the US-EAST-1 region became unavailable for about four hours. Thousands of websites and apps stopped working, and even...
Amazon S3 is extremely durable, but a single region can still become unavailable. Here is how to design S3-backed workloads to keep running — or at least...
Outages are rare enough that teams forget how to handle them. A tabletop exercise — a structured discussion of a realistic scenario — is the cheapest way to...
The short version: In 2017, a mistyped command at Amazon took down a core storage service in one region for about four hours, and thousands of websites went...
At AWS re:Invent in late 2016, Amazon announced AWS Shield, its managed DDoS protection service. The headline was simple: every AWS customer would get...
AWS Shield Standard protects every AWS account against common network-layer DDoS attacks automatically. Application-layer attacks need more work. Here is...
Use this checklist to check whether an AWS-hosted application is ready for a denial-of-service attack. Each "no" is a gap to plan for.
The short version: Every AWS customer gets Shield Standard free, and it handles the most common DDoS attacks. Shield Advanced is a paid upgrade that adds...
In December 2016, Yahoo disclosed that data from roughly one billion user accounts had been stolen in 2013. Months earlier it had disclosed a separate 2014...
Turning on multi-factor authentication for every Microsoft 365 user is the single most effective identity control you can deploy. It is also the change most...
Credential stuffing uses username and password pairs leaked from other breaches to try to sign in to your Microsoft 365 tenant. Detection is about spotting...
The short version: When a big company like Yahoo loses billions of passwords, your company is also at risk. Your employees reuse passwords, and attackers...
On October 21, 2016, a large share of the US internet seemed to stop working. Twitter, Netflix, Reddit, GitHub, Spotify and dozens of other services became...
The 2016 Dyn attack proved that DNS can take a healthy application offline. Here is a practical way to design DNS and DDoS protection for workloads running...
DDoS attacks against DNS and web front ends are noisy, which makes them easy to notice and hard to diagnose quickly. The goal of detection is speed: confirm...
The short version: In October 2016, an attack on one DNS company, Dyn, made major websites unreachable for hours. The websites were fine. A supplier they...