{"id":420,"date":"2017-07-14T22:20:52","date_gmt":"2017-07-14T22:20:52","guid":{"rendered":"https:\/\/eset-blog.aist.fun\/patching-your-questions-answered\/"},"modified":"2019-05-29T12:06:54","modified_gmt":"2019-05-29T12:06:54","slug":"patching-your-questions-answered","status":"publish","type":"post","link":"https:\/\/blog.eset.ee\/et\/en\/2017\/07\/14\/patching-your-questions-answered\/","title":{"rendered":"Patching: Your questions answered"},"content":{"rendered":"<p class=\"wls-paragraph\">Three years after <a href=\"https:\/\/www.microsoft.com\/en-gb\/windowsforbusiness\/end-of-xp-support\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft said<\/a> it was ending support for Windows XP, <a href=\"https:\/\/blogs.technet.microsoft.com\/msrc\/2017\/05\/12\/customer-guidance-for-wannacrypt-attacks\/\" target=\"_blank\" rel=\"noopener noreferrer\">it announced<\/a>&nbsp;on May 12th 2017 that&nbsp;it was issuing a security update for the operating system, as well as Windows 8.0 and Windows Server 2003, both of which are in custom support only.&nbsp;That\u2019s two months after the same patch was released for supported versions of Windows.<\/p>\n<p class=\"wls-paragraph\">The reason was all too clear. Earlier that day, cybercriminals launched a ransomware attack that exploited vulnerabilities in these older systems. <a href=\"https:\/\/www.welivesecurity.com\/2017\/05\/13\/wanna-cryptor-ransomware-outbreak\/\" target=\"_blank\" rel=\"noopener noreferrer\">WannaCryptor<\/a> \u2013 aka WannaCry \u2013 was global in scope, affecting organizations in some 150 countries. Something out of the ordinary had to be done.<\/p>\n<p class=\"wls-paragraph\">\u201cWe are taking the highly unusual step of providing a security update for all customers to protect Windows platforms that are in custom support only,\u201d Phillip Misner, Principal Security Group Manager at Microsoft Security Response Center, said at the time.<\/p>\n<p class=\"wls-paragraph\">\u201cSeeing businesses and individuals affected by cyberattacks, such as the ones reported today, was painful.\u201d<\/p>\n<p class=\"wls-paragraph\">The security update was an example of patching, a term yet unknown to many, but extremely commonplace and well understood by the infosec community. In this feature, we answer key questions about patches.<\/p>\n<h2><b>What is a patch?<\/b><\/h2>\n<p class=\"wls-paragraph\">First things first. If you\u2019ve ever had to fix a puncture in a bike tyre, you\u2019re halfway there to understanding the concept of a patch. In the context of security, \u201cpatches\u201d are issued by companies when security flaws are uncovered.<\/p>\n<p class=\"wls-paragraph\">By way of a more specific definition, a security patch is an update to a piece of software or program to fix a bug or vulnerability, as well as a way to improve it. The same concept as taping up a hole in a tyre, but in the digital world.<\/p>\n<h2><b>What\u2019s the difference between a patch and a security update?<\/b><\/h2>\n<p class=\"wls-paragraph\">All patches are updates, but not all updates are patches. Whereas patches are used within the context of fixing something specific, security updates are implemented for general security purposes rather than, for example,&nbsp;targeting a particular type of malware&nbsp;or vulnerability.<\/p>\n<h2><b>Could Microsoft have stopped WannaCryptor?<\/b><\/h2>\n<p class=\"wls-paragraph\">While it\u2019s important to be clear that Microsoft does not accept responsibility for the ransomware\u2019s spread, the patch it issued in <a href=\"https:\/\/technet.microsoft.com\/en-us\/library\/security\/ms17-010.aspx\" target=\"_blank\" rel=\"noopener noreferrer\">March<\/a> only protected \u201cnewer Windows systems and computers that had enabled Windows Update\u201d.<\/p>\n<p class=\"wls-paragraph\">In defense of the tech giant, the original patch was not installed by many organizations. The FT <a href=\"https:\/\/www.ft.com\/content\/348d4f7a-3808-11e7-821a-6027b8a20f23?mhq5j=e2\" target=\"_blank\" rel=\"noopener noreferrer\">reported<\/a> that Microsoft\u2019s Phillip Misner claims the patch released in March \u201cwould have protected users against WannaCryptor, provided they installed the fix on their machines\u201d.<\/p>\n<p class=\"wls-paragraph\">The fact it was necessary to launch a new patch for unsupported versions of its operating system may speak for itself, but it is indisputable that we as individuals need to take responsibility ourselves for installing updates when we can.<\/p>\n<h2><b>How can I install a patch?<\/b><\/h2>\n<p class=\"wls-paragraph\">Installing an update to prevent an attack is the easy part. Here are three ways you can make sure your security is as watertight as possible:<\/p>\n<ol>\n<li>ESET has a <a href=\"http:\/\/support.eset.com\/kb6481\/\" target=\"_blank\" rel=\"noopener noreferrer\">free tool<\/a> to make sure the Windows vulnerabilities exploited by WannaCryptor are patched.<\/li>\n<li>Microsoft users should head to <a href=\"http:\/\/www.catalog.update.microsoft.com\/Search.aspx?q=KB4012598\" target=\"_blank\" rel=\"noopener noreferrer\">this link<\/a> to download and install relevant updates.<\/li>\n<li>If you fall victim to a cyberattack and need to remove malware, try using this <a href=\"https:\/\/support.microsoft.com\/en-us\/help\/890830\/remove-specific-prevalent-malware-with-windows-malicious-software-removal-tool\" target=\"_blank\" rel=\"noopener noreferrer\">tool<\/a> provided by Microsoft.<\/li>\n<\/ol>\n<p class=\"wls-paragraph\">If you\u2019re an Apple user, yes \u2013 you might be <a href=\"https:\/\/www.welivesecurity.com\/2017\/05\/16\/apple-users-advised-update-software-now-new-security-patches-released\/\" target=\"_blank\" rel=\"noopener noreferrer\">less likely<\/a> to suffer an attack, but it\u2019s not time to relax just yet: you\u2019re far from immune. Follow <a href=\"https:\/\/support.apple.com\/en-us\/HT201222\" target=\"_blank\" rel=\"noopener noreferrer\">this link<\/a> to install updates on your device.<\/p>\n<h2><b>Can patches stop the spread of a ransomware attack?<\/b><\/h2>\n<p class=\"wls-paragraph\">Patches can help stop malware from spreading, but they aren\u2019t guaranteed to prevent or halt a cyberattack.<\/p>\n<p class=\"wls-paragraph\">One of the main challenges firms often experience during an attack is that they lack the capacity to apply patches quickly to a high number of machines, because they can\u2019t allow their machines to be out of action for a prolonged amount of time.<\/p>\n<p class=\"wls-paragraph\">However, it may be mildly reassuring to know that the attackers made errors that allowed this malware to be stifled, limiting its already significant damage \u2026 but we won\u2019t always be so fortunate.<\/p>\n<p class=\"wls-paragraph\">So, the best line of defense to <a href=\"https:\/\/www.welivesecurity.com\/2017\/05\/18\/protected-against-wannacryptor\/\">fight ransomware<\/a> remains to be updating your systems as and when updates become available. Don\u2019t put it off; do it now (and<a href=\"https:\/\/www.welivesecurity.com\/2016\/03\/31\/ransomware-threat-highlights-why-backing-up-data-is-essential\/\" target=\"_blank\" rel=\"noopener noreferrer\"> back up your data<\/a>).<\/p>\n<h2><b>So, are we safe now?<\/b><\/h2>\n<p class=\"wls-paragraph\">The WannaCryptor virus is not about to miraculously evaporate into a thin mist. One recent <a href=\"http:\/\/www.bbc.co.uk\/news\/world-australia-40363784\" target=\"_blank\" rel=\"noopener noreferrer\">flare-up<\/a>saw it preventing speeding drivers in Australia from being fined. The malware was accidentally uploaded to the camera network, affecting 55 traffic cameras.<\/p>\n<p class=\"wls-paragraph\">Less user-friendly and far more dangerous, a more recent <a href=\"https:\/\/www.welivesecurity.com\/2017\/06\/27\/new-ransomware-attack-hits-ukraine\/\" target=\"_blank\" rel=\"noopener noreferrer\">global attack<\/a> displayed similar traits to WannaCryptor, as the malware in both attacks identified and exploited the same weaknesses.<\/p>\n<p class=\"wls-paragraph\">It targeted the Ukranian government, as well as banks and hospitals in the country, and also, more globally, affected the shipping company Maersk in Denmark, and advertising company WPP in the UK. But unlike WannaCryptor, disconcertingly, the attack brought with it an element of mystery: one week later, experts were \u201c<a href=\"http:\/\/www.bbc.com\/future\/story\/20170704-the-day-a-mysterious-cyber-attack-crippled-ukraine\" target=\"_blank\" rel=\"noopener noreferrer\">still not entirely clear why it happened<\/a>, or who was behind it\u201d.<\/p>\n<p class=\"wls-paragraph\">Brad Smith, Microsoft\u2019s President and Chief Legal Officer, <a href=\"https:\/\/blogs.microsoft.com\/on-the-issues\/2017\/05\/14\/need-urgent-collective-action-keep-people-safe-online-lessons-last-weeks-cyberattack\/#sm.00000rdqudzte2egwr6fq5df75ikc\" target=\"_blank\" rel=\"noopener noreferrer\">wrote<\/a>: \u201cAs cybercriminals become more sophisticated, there is simply no way for customers to protect themselves against threats unless they update their systems.\u201d<\/p>\n<p class=\"wls-paragraph\">This simply highlights the importance of staying vigilant and taking responsibility. It\u2019s imperative to take heed of Smith\u2019s advice. Update your Windows machines, install a security solution, make backups often and keep at least one of them&nbsp; offline, change your passwords, beware of <a href=\"https:\/\/www.welivesecurity.com\/2017\/05\/04\/teach-person-phishing\/\" target=\"_blank\" rel=\"noopener noreferrer\">phishing emails<\/a>&nbsp;and implement two-factor authentication. It\u2019s only by a concentrated effort en-masse that we can defeat the next variant of WannaCryptor, or indeed any other threat.<\/p>\n<p>Source: <a href=\"https:\/\/www.welivesecurity.com\/2017\/07\/14\/patching-questions-answered\/\"><strong>WeLiveSecurity<\/strong><\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Three years after Microsoft said it was ending support for Windows XP, it announced&nbsp;on May 12th 2017 that&nbsp;it was issuing a security update for the operating system, as well as Windows 8.0 and Windows Server 2003, both of which are in custom support only.&nbsp;That\u2019s two months after the same patch was released for supported versions [&hellip;]<\/p>\n","protected":false},"author":5,"featured_media":1821,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[2905,2902,167],"tags":[],"class_list":["post-420","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-devices","category-home-family","category-privacy"],"acf":[],"amp_enabled":true,"_links":{"self":[{"href":"https:\/\/blog.eset.ee\/et\/en\/wp-json\/wp\/v2\/posts\/420","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blog.eset.ee\/et\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blog.eset.ee\/et\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blog.eset.ee\/et\/en\/wp-json\/wp\/v2\/users\/5"}],"replies":[{"embeddable":true,"href":"https:\/\/blog.eset.ee\/et\/en\/wp-json\/wp\/v2\/comments?post=420"}],"version-history":[{"count":0,"href":"https:\/\/blog.eset.ee\/et\/en\/wp-json\/wp\/v2\/posts\/420\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/blog.eset.ee\/et\/en\/wp-json\/wp\/v2\/media\/1821"}],"wp:attachment":[{"href":"https:\/\/blog.eset.ee\/et\/en\/wp-json\/wp\/v2\/media?parent=420"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blog.eset.ee\/et\/en\/wp-json\/wp\/v2\/categories?post=420"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blog.eset.ee\/et\/en\/wp-json\/wp\/v2\/tags?post=420"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}