All Article Properties:
{
"access_control": false,
"status": "publish",
"objectType": "Article",
"id": "61293",
"signature": "Article:61293",
"url": "https://staging.dailymaverick.co.za/article/2017-06-28-ransomware-wave-seemed-aimed-at-old-flaw-and-ukraine/",
"shorturl": "https://staging.dailymaverick.co.za/article/61293",
"slug": "ransomware-wave-seemed-aimed-at-old-flaw-and-ukraine",
"contentType": {
"id": "1",
"name": "Article",
"slug": "article"
},
"views": 0,
"comments": 0,
"preview_limit": null,
"excludedFromGoogleSearchEngine": 0,
"title": "'Ransomware' wave seemed aimed at old flaw and Ukraine",
"firstPublished": "2017-06-28 05:26:27",
"lastUpdate": "2017-06-28 05:26:27",
"categories": [
{
"id": "1855",
"name": "Newsdeck",
"signature": "Category:1855",
"slug": "newsdeck",
"typeId": {
"typeId": "1",
"name": "Daily Maverick",
"slug": "",
"includeInIssue": "0",
"shortened_domain": "",
"stylesheetClass": "",
"domain": "staging.dailymaverick.co.za",
"articleUrlPrefix": "",
"access_groups": "[]",
"locale": "",
"preview_limit": null
},
"parentId": null,
"parent": [],
"image": "",
"cover": "",
"logo": "",
"paid": "0",
"objectType": "Category",
"url": "https://staging.dailymaverick.co.za/category/newsdeck/",
"cssCode": "",
"template": "default",
"tagline": "",
"link_param": null,
"description": "",
"metaDescription": "",
"order": "0",
"pageId": null,
"articlesCount": null,
"allowComments": "1",
"accessType": "freecount",
"status": "1",
"children": [],
"cached": true
}
],
"content_length": 2521,
"contents": "\r\n<p>The first reports of trouble came from Ukrainian banks, Kiev's main airport and Rosneft, in a major incident reminiscent of the recent WannaCry virus.</p>\r\n<p>WannaCry was a version of ransomware that, once in a computer, locked away data from users who were then told to pay to have access returned to their own files.</p>\r\n<p>The <g class=\"gr_ gr_35 gr-alert gr_spell gr_inline_cards gr_run_anim ContextualSpelling multiReplace\" id=\"35\" data-gr-id=\"35\">bedeviling</g> onslaught Tuesday was also being referred to as ransomware by US software titan Microsoft and security specialists.</p>\r\n<p>\"Our initial analysis found that the ransomware uses multiple techniques to spread, including one which was addressed by a security update previously provided for all platforms from Windows XP to Windows 10 (MS17-010),\" a Microsoft spokesperson told AFP.</p>\r\n<p>After the WannaCry scourge in May, Microsoft called on people to protect machines with the MS17-010 patch.</p>\r\n<p>The flaw -- and the means to exploit it -- had previously been disclosed in pirated documents about cyber weapons at the US National Security Agency.</p>\r\n<p>Microsoft said that its anti-virus software detects and removes the ransomware used in the latest attack.</p>\r\n<p>Microsoft is continuing to investigate the latest cyberattack and will take necessary steps to protect customers, the spokesperson said.</p>\r\n<p>People were also urged to be wary of clicking on email attachments or shared <g class=\"gr_ gr_38 gr-alert gr_gramm gr_inline_cards gr_run_anim Punctuation only-del replaceWithoutSep\" id=\"38\" data-gr-id=\"38\">links,</g> since that is a common trick used to unleash malicious code on computers.</p>\r\n<p>\"As ransomware also typically spreads via email, customers should exercise caution when opening unknown files,\" the Microsoft spokesperson said.</p>\r\n<p>Identification of the way the latest ransomware initially got into machines was proving challenging, and the use of email was not confirmed, according to a post by Cisco Talos threat intelligence.</p>\r\n<p>\"Based on observed in-the-wild <g class=\"gr_ gr_42 gr-alert gr_spell gr_inline_cards gr_run_anim ContextualSpelling multiReplace\" id=\"42\" data-gr-id=\"42\">behaviors</g>, the lack of a known, viable external spreading mechanism and other research we believe it is possible that some infections may be associated with software update systems for a Ukrainian tax accounting package called <g class=\"gr_ gr_34 gr-alert gr_spell gr_inline_cards gr_run_anim ContextualSpelling ins-del multiReplace\" id=\"34\" data-gr-id=\"34\">MeDoc</g>,\" Cisco Talos wrote.</p>\r\n<p>Ukraine's central bank said several lenders had been hit in the country, hindering operations and leading the regulator to warn other financial institutions to tighten security measures.</p>\r\n<p>The virus is \"spreading around the world, a large number of countries are affected,\" Costin Raiu, a researcher at the Moscow-based Kaspersky Lab said in a Twitter post.</p>\r\n<p>The <g class=\"gr_ gr_37 gr-alert gr_spell gr_inline_cards gr_run_anim ContextualSpelling ins-del multiReplace\" id=\"37\" data-gr-id=\"37\">cryptolocker</g> demands $300 in bitcoins and does not name the encrypting program, which makes finding a solution difficult, Group IB spokesman Evgeny Gukov said. DM</p>",
"teaser": "'Ransomware' wave seemed aimed at old flaw and Ukraine",
"externalUrl": "",
"sponsor": null,
"authors": [
{
"id": "504",
"name": "AFP",
"image": "",
"url": "https://staging.dailymaverick.co.za/author/afp/",
"editorialName": "afp",
"department": "",
"name_latin": ""
}
],
"description": "",
"keywords": [
{
"type": "Keyword",
"data": {
"keywordId": "5505",
"name": "Security",
"url": "https://staging.dailymaverick.co.za/keyword/security/",
"slug": "security",
"description": "",
"articlesCount": 0,
"replacedWith": null,
"display_name": "Security",
"translations": null
}
},
{
"type": "Keyword",
"data": {
"keywordId": "10244",
"name": "Cybercrime",
"url": "https://staging.dailymaverick.co.za/keyword/cybercrime/",
"slug": "cybercrime",
"description": "",
"articlesCount": 0,
"replacedWith": null,
"display_name": "Cybercrime",
"translations": null
}
},
{
"type": "Keyword",
"data": {
"keywordId": "10246",
"name": "Cyberwarfare",
"url": "https://staging.dailymaverick.co.za/keyword/cyberwarfare/",
"slug": "cyberwarfare",
"description": "",
"articlesCount": 0,
"replacedWith": null,
"display_name": "Cyberwarfare",
"translations": null
}
},
{
"type": "Keyword",
"data": {
"keywordId": "12438",
"name": "Cyberattacks",
"url": "https://staging.dailymaverick.co.za/keyword/cyberattacks/",
"slug": "cyberattacks",
"description": "",
"articlesCount": 0,
"replacedWith": null,
"display_name": "Cyberattacks",
"translations": null
}
},
{
"type": "Keyword",
"data": {
"keywordId": "12439",
"name": "Security breaches",
"url": "https://staging.dailymaverick.co.za/keyword/security-breaches/",
"slug": "security-breaches",
"description": "",
"articlesCount": 0,
"replacedWith": null,
"display_name": "Security breaches",
"translations": null
}
},
{
"type": "Keyword",
"data": {
"keywordId": "12440",
"name": "Ransomware",
"url": "https://staging.dailymaverick.co.za/keyword/ransomware/",
"slug": "ransomware",
"description": "",
"articlesCount": 0,
"replacedWith": null,
"display_name": "Ransomware",
"translations": null
}
},
{
"type": "Keyword",
"data": {
"keywordId": "12441",
"name": "WannaCry ransomware attack",
"url": "https://staging.dailymaverick.co.za/keyword/wannacry-ransomware-attack/",
"slug": "wannacry-ransomware-attack",
"description": "",
"articlesCount": 0,
"replacedWith": null,
"display_name": "WannaCry ransomware attack",
"translations": null
}
},
{
"type": "Keyword",
"data": {
"keywordId": "12443",
"name": "Malware",
"url": "https://staging.dailymaverick.co.za/keyword/malware/",
"slug": "malware",
"description": "",
"articlesCount": 0,
"replacedWith": null,
"display_name": "Malware",
"translations": null
}
},
{
"type": "Keyword",
"data": {
"keywordId": "12445",
"name": "EternalBlue",
"url": "https://staging.dailymaverick.co.za/keyword/eternalblue/",
"slug": "eternalblue",
"description": "",
"articlesCount": 0,
"replacedWith": null,
"display_name": "EternalBlue",
"translations": null
}
},
{
"type": "Keyword",
"data": {
"keywordId": "16744",
"name": "Antivirus software",
"url": "https://staging.dailymaverick.co.za/keyword/antivirus-software/",
"slug": "antivirus-software",
"description": "",
"articlesCount": 0,
"replacedWith": null,
"display_name": "Antivirus software",
"translations": null
}
},
{
"type": "Keyword",
"data": {
"keywordId": "16745",
"name": "Computer virus",
"url": "https://staging.dailymaverick.co.za/keyword/computer-virus/",
"slug": "computer-virus",
"description": "",
"articlesCount": 0,
"replacedWith": null,
"display_name": "Computer virus",
"translations": null
}
}
],
"short_summary": null,
"source": null,
"related": [],
"options": [],
"summary": "A global wave of cyberattacks on Tuesday exploited an already patched vulnerability in Windows software and appeared to have Ukraine as a primary target, according to computer security specialists.",
"template_type": null,
"dm_custom_section_label": null,
"elements": [],
"seo": {
"search_title": "'Ransomware' wave seemed aimed at old flaw and Ukraine",
"search_description": "\r\n<p>The first reports of trouble came from Ukrainian banks, Kiev's main airport and Rosneft, in a major incident reminiscent of the recent WannaCry virus.</p>\r\n<p>WannaCry was a version of ransomware",
"social_title": "'Ransomware' wave seemed aimed at old flaw and Ukraine",
"social_description": "\r\n<p>The first reports of trouble came from Ukrainian banks, Kiev's main airport and Rosneft, in a major incident reminiscent of the recent WannaCry virus.</p>\r\n<p>WannaCry was a version of ransomware",
"social_image": ""
},
"cached": true,
"access_allowed": true
}