The Free Press Journal

Beware of the ‘BlueKeep’

-

The “BlueKeep” remote code execution vulnerabil­ity, which could have an effect similar to the WannaCry bug from 2017, is currently attacking vulnerable machines that are apparently compromise­d for cryptocurr­ency mining purposes, according to media reports. The BlueKeep vulnerabil­ity exists in unpatched versions of Windows Server 2003, Windows XP, Windows Vista, Windows 7, Windows Server 2008 and Windows Server 2008 R2.

According to security researcher Kevin Beaumont, several honeypots in his EternalPot RDP honeypot network started to crash and reboot. They have been active for almost half a year and this is the first time they came down. For some reason, the machines in Australia did not crash, the researcher said in a tweet, Bleeping Computer reported on Sunday. Security researcher­s, including Beaumont who originally named the vulnerabil­ity and Marcus Hutchins, also known as “MalwareTec­h”, who was responsibl­e for hitting the kill switch that stopped the WannaCry bug, have confirmed that a widespread BlueKeep exploit attack is now currently underway.

Interestin­gly, BlueeKeep has the ability to spread itself from one machine to another, while the attackers are searching for vulnerable unpatched Windows systems that have Remote Desktop Services (RDP) 3389 ports exposed to the Internet. For now though, this looks like being an attack campaign with a cryptocurr­ency miner payload, according to Forbes.

 ?? PIC: MALWARE.NEWS ??
PIC: MALWARE.NEWS

Newspapers in English

Newspapers from India