惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

C
Check Point Blog
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
L
LangChain Blog
云风的 BLOG
云风的 BLOG
M
MIT News - Artificial intelligence
A
About on SuperTechFans
J
Java Code Geeks
量子位
博客园 - 三生石上(FineUI控件)
博客园 - Franky
博客园_首页
H
Hackread – Cybersecurity News, Data Breaches, AI and More
IT之家
IT之家
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
Apple Machine Learning Research
Apple Machine Learning Research
Engineering at Meta
Engineering at Meta
雷峰网
雷峰网
D
DataBreaches.Net
人人都是产品经理
人人都是产品经理
Martin Fowler
Martin Fowler
有赞技术团队
有赞技术团队
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻

Security Affairs

Agent’s claims on WhatsApp access spark security concerns Meta accused of violating DSA by failing to safeguard minors Large-scale Roblox hacking operation shut down by Ukrainian authorities CVE-2026-42208: LiteLLM bug exploited 36 hours after its disclosure Internet censorship index reveals Russia’s lead and widespread content blocking All supported cPanel versions hit by critical auth bug, now patched U.S. CISA adds Microsoft Windows Shell and ConnectWise ScreenConnect flaws to its Known Exploited Vulnerabilities catalog ShinyHunters exploit Anodot incident to target Vimeo CVE-2026-3854 GitHub flaw enables remote code execution Signal Phishing Campaign Targets German Officials in Suspected Russian Operation Microsoft fixes Entra ID flaw enabling privilege escalation New Android spyware Morpheus linked to Italian surveillance firm NCSC launches SilentGlass, a plug-in device to secure HDMI and DisplayPort links Medtronic discloses security incident after ShinyHunters claimed theft of 9M+ records Chinese spy posed as researcher in spear-phishing campaign targeting NASA to steal defense software LINKEDIN BROWSERGATE Firefox bug CVE-2026-6770 enabled cross-site tracking and Tor fingerprinting Fast16: Pre-Stuxnet malware that targeted precision engineering software Italy moves to extradite Chinese national to the U.S. over hacking charges U.S. utility giant Itron discloses a security breach Critical bug in CrowdStrike LogScale let attackers access files GopherWhisper: new China-linked APT targets Mongolia with Go-based malware SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 94 Trigona ransomware adopts custom tool to steal data and evade detection Security Affairs newsletter Round 574 by Pierluigi Paganini – INTERNATIONAL EDITION U.S. CISA adds SimpleHelp, Samsung, and D-Link flaws to its Known Exploited Vulnerabilities catalog Over 400,000 sites at risk as hackers exploit Breeze Cache plugin flaw (CVE-2026-3844) CISA reports persistent FIRESTARTER backdoor on Cisco ASA device in federal network 12-year-old Pack2TheRoot bug lets Linux users gain root privileges Signal phishing campaign targets Germany’s Bundestag President Julia Klöckner
WannaCry, the ransomware attack that changed the history ...
Pierluigi Pa · 2026-05-12 · via Security Affairs

WannaCry showed how unpatched flaws and leaked cyber tools can cripple global systems, reshaping cybersecurity defenses worldwide.

In memory of the day the digital world was shaken, but learned to fight back.

The WannaCry ransomware attack represents one of the most significant events in recent cybersecurity history, not only for its global scale but also for the technical and geopolitical implications it raised. Analyzing its history means understanding how known vulnerabilities, advanced tools, and delays in mitigation can converge into an event capable of disrupting critical infrastructure worldwide.

WannaCry emerged on May 12, 2017 by exploiting a vulnerability in the SMBv1 protocol of Microsoft Windows (CVE-2017-0144 aka EternalBlue). This vulnerability, which was addressed by the Microsoft security patch MS17-010 in March 2017, allowed remote code execution without authentication. The most critical detail is that the exploit used, known as EternalBlue, was not developed by common cybercriminals but derived from offensive tools attributed to the National Security Agency (NSA), later leaked by the hacker group Shadow Brokers.

This combination made WannaCry particularly effective. It was not a traditional ransomware spread via phishing, but a worm capable of autonomously propagating within networks.

On that day in May, WannaCry began spreading rapidly, infecting over 200,000 systems in more than 150 countries within hours. Among the countries most affected were Spain, United Kingdom, United States, China, Portugal, Vietnam, Russia, and Ukraine, with particular impact on British hospital IT systems and Spanish telecommunications networks.

Italy was also affected by the attack, and the case was handled by the CNAIPIC, the cybercrime operations center of the Polizia Postale. The speed of propagation was largely due to the widespread presence of unpatched systems, especially outdated Windows versions like Windows XP.

Infection mechanism and behavior

Once inside a system, WannaCry encrypted files using strong cryptographic algorithms and displayed a ransom demand in Bitcoin. The requested payment was relatively low, around $300, but increased over time to pressure victims into paying quickly.

From a technical perspective, the real innovation was its automated lateral movement. Using EternalBlue, the malware scanned networks for other vulnerable systems and replicated itself without human interaction. This behavior made it more similar to a classic worm than to traditional ransomware.

A crucial moment in WannaCry’s history was the accidental discovery of a “kill switch.” Security researcher Marcus Hutchins (aka MalwareTech), while analyzing the code, noticed that the malware attempted to connect to an unregistered domain (hxxp://www[.]iuqerfsodp9ifjaposdfjhgosurijfaewrwergwea[.]com).

By registering that domain, he effectively slowed and partially stopped the worm’s global spread. This mechanism was likely intended as an anti-analysis technique, but it ended up playing a key role in mitigating the attack.

Attribution and lessons learned

Subsequent investigations attributed the attack to groups linked to North Korea, particularly the Lazarus Group. This attribution, supported by several governments including the United States and the United Kingdom, highlighted how cyber warfare tools can be repurposed in criminal or hybrid operations.

The WannaCry case also sparked intense debate about how governments manage software vulnerabilities. The fact that an intelligence-grade exploit escaped control and was used globally exposed the risks associated with stockpiling cyber weapons.

WannaCry marked a turning point in how cyber risk is perceived. It demonstrated that failing to apply security patches can lead to systemic consequences. Microsoft had released the necessary security update months before the attack, yet many organizations had not implemented it.

Another key lesson concerns network segmentation. The worm’s ability to move laterally exposed weaknesses in internal infrastructures that lacked proper isolation controls.

Finally, WannaCry emphasized the importance of international cooperation in cyber incident response. The timely sharing of technical information helped limit the damage and enabled faster development of countermeasures.

Years later, WannaCry remains a landmark case showing how known vulnerabilities, advanced tools, and organizational shortcomings can combine into a devastating cyberattack. It was neither the most sophisticated nor the most profitable ransomware, but it was undoubtedly one of the most impactful.

Its legacy is still visible today in modern security practices, which place greater emphasis on patch management, network resilience, and preparedness for large-scale attacks.

About the author: Salvatore Lombardo (@Slvlombardo)

Electronics engineer and Clusit member, for some time now, espousing the principle of conscious education, he has been writing for several online magazine on information security. He is also the author of the book “La Gestione della Cyber Security nella Pubblica Amministrazione”. “Education improves awareness” is his slogan.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, ransomware)