Windows administrators around the world are working overtime to update their Windows equipment after Microsoft released a patch on January 14 for critical security vulnerabilities in Microsoft 10 and Microsoft Server 2016, 2019, and more. Now, more than 900 million devices that run on these programs are in need of an update!

One of the critical vulnerabilities in Windows CryptoAPI (which allows organizations to “sign” their applications and validate the app’s authenticity) would allow malware to be disguised as trustworthy, effectively fooling users and antivirus software. Read about all the vulnerabilities here.

Let’s Recap: Where Have We Seen This Before?

The National Security Agency (NSA) discovered another vulnerability in Microsoft systems years ago and weaponized the vulnerability, calling it Eternal Blue. In 2017, the NSA disclosed the weakness to Microsoft, who then patched the bug and released the software fix to the public…. Is this starting to sound familiar?

Here’s where it went wrong: after Microsoft released the patches, Eternal Blue was leaked by a hacker group called the Shadow Brokers to the web. One month later, the worldwide WannaCry ransomware attack unfolded, exploiting unpatched computers.

The NSA seems to be trying to turn things around this time by disclosing the bugs to Microsoft. Imagine that day at Microsoft.

So How Can We Prevent WannaCry Part Two?

1. Update! Update all your computers using Microsoft 10 and your Windows Servers. Don’t make the mistake of holding off the updates for a more convenient time. Hackers are going to find that pretty convenient for them, too! Not updating your computer is like sitting in the road, seeing a car speeding towards you, and saying, “I’ll move later.” Later just might be too late.

2. Backup your data. Whether you are responsible for an IT infrastructure supporting 10,000 employees or you are managing your home computer, BACKUP YOUR DATA. If you have an existing backup system, check your backups. Ask yourself, Could my organization survive if we lost all of our data and had to restore our backups? Are our backups current and working? How long would it take us to restore from backups? If you are not satisfied with any of the answers to those questions, do something about it.

How We Can Help

