---
title: "WannaCry: Nothing New Here Apart from a Catchy Name"
description: Insights into the WannaCry breach and why it's not particularly new or innovative - both in threat vectors and effective preventative approach.
image: https://www.securitycentric.com.au/hubfs/wannacry.jpg
---

[![logo (1)](https://www.securitycentric.com.au/hs-fs/hubfs/SecurityCentric_August2018/Images/logo%20(1).png?width=400&height=53&name=logo%20(1).png "logo (1)")](https://www.securitycentric.com.au)

[![Contact Us](https://hubspot-no-cache-ap1-prod.s3.amazonaws.com/cta/default/4774443/0ada3cc7-a403-4ef0-bf48-298e98cb9f05.png)](https://hubspot-cta-redirect-ap1-prod.s3.amazonaws.com/cta/redirect/4774443/0ada3cc7-a403-4ef0-bf48-298e98cb9f05)

**

** **

[![logo (1)](https://www.securitycentric.com.au/hs-fs/hubfs/SecurityCentric_August2018/Images/logo%20(1).png?width=423&height=56&name=logo%20(1).png "logo (1)")](https://www.securitycentric.com.au)

[![Contact Us](https://hubspot-no-cache-ap1-prod.s3.amazonaws.com/cta/default/4774443/0ada3cc7-a403-4ef0-bf48-298e98cb9f05.png)](https://hubspot-cta-redirect-ap1-prod.s3.amazonaws.com/cta/redirect/4774443/0ada3cc7-a403-4ef0-bf48-298e98cb9f05)

**

** **

Search

**Menu**

** **

[![Contact Us](https://hubspot-no-cache-ap1-prod.s3.amazonaws.com/cta/default/4774443/0ada3cc7-a403-4ef0-bf48-298e98cb9f05.png)](https://hubspot-cta-redirect-ap1-prod.s3.amazonaws.com/cta/redirect/4774443/0ada3cc7-a403-4ef0-bf48-298e98cb9f05)

[**Cyber Security News & Current Events](https://www.securitycentric.com.au/blog)

# WannaCry: Nothing New Here Apart from a Catchy Name

by [Sash](https://www.securitycentric.com.au/blog/author/sash), on 17/05/2017 1:17:00 PM

Even the catchy name is not particularly innovative (Heartbleed has to take that prize over others such as BEAST and POODLE).

As someone intimately involved in cyber security on a daily basis, I cannot understand why some events get so much attention whilst much more fundamentally-important issues remain off the radar of the C-suite who actively manage business risk.

![wannacry](https://www.securitycentric.com.au/hs-fs/hubfs/wannacry.jpg?width=376&name=wannacry.jpg)Over the weekend we have a two month old exploitable vulnerability that was used to exploit unpatched assets. If I had a thousandth of a bitcoin for every time that has occurred I would be writing this from my superyacht moored off the south of France.

OK so I'll acknowledge those not from an IT background may find the fact that the exploit was part of an NSA toolkit interesting. Sure it is, but it's just another vulnerability in a database of hundreds of thousands. The impact was significant, but that is often the case. The Renault Formula 1 team was also compromised during a race weekend which reportedly affected their lap times during qualifying. I find that interesting but I'm sure there are plenty of interesting risk realisation scenarios for any number of vulnerability exploitation scenarios.

I've presented to rooms full of professionals who have just heard from vendors about how terrific their products are, and how they will solve all of their worldly (cyber security) problems, and I tell them to ignore all of that and focus on getting the basics right, one of which is vulnerability management. The rest falls into place after that. It's not rocket science - it's barely any science - malicious actors use vulnerabilities to compromise an environment, so how about focussing on the mechanism that enables the exploitation.

It's hardly anything new either. David Jones and Kmart were compromised due to an unpatched WebSphere vulnerability, something a scheduled external scan should have identified. The curious programming "feature" related to the domain used to sinkhole it made it even more interesting, with the David vs Goliath story of a young researcher stopping a global spread of malware. Interesting, but it's really just another strain of ransomware using a recent vulnerability to spread, sprinkled with some "NSA" here and some "kill-switch" there.

The only thing that makes me wanna cry is the reactive nature of the industry to a problem that is consistent and ever-present, but which can be solved with fundamental risk management rather than your latest APT-cloud-machine-learning-adaptive-heuristic-HTML5dashboard-hybrid-killhain-threat-intel-broad-spectrum shiny new cyber toy.

 

**For a 'matched' music selection (think matching wines) you may consider Australia's very own Keith:**

[![Open in Spotify](https://www.securitycentric.com.au/hs-fs/hubfs/keithurban.png?width=300&name=keithurban.png)](https://open.spotify.com/track/61hmCqoIlTJjcVMMLhcH5n)

## Comments

### Finally, an actionable blog

The purpose of this blog is to make available the real-world lessons, experience, observations and mistakes that are part of the daily life of a group of cyber security professionals.

Read about:

- What mistakes organisations are making (anonymously of course!)
- What effective actions are available to quickly and economically achieve effective protection (without buying new kit)
- Trends we're seeing, via our incident response and forensic investigation capabilities
- And sometimes, just frustrations about what is wrong with cyber :|

- [Recent](https://www.securitycentric.com.au/blog/wannacry-nothing-new-here-apart-from-a-catchy-name#recent)
- [Topics](https://www.securitycentric.com.au/blog/wannacry-nothing-new-here-apart-from-a-catchy-name#topics)
- [Archive](https://www.securitycentric.com.au/blog/wannacry-nothing-new-here-apart-from-a-catchy-name#archive)

- [Authentication (6)](https://www.securitycentric.com.au/blog/tag/authentication)
- [Cloud Security (1)](https://www.securitycentric.com.au/blog/tag/cloud-security)
- [Compliance (11)](https://www.securitycentric.com.au/blog/tag/compliance)
- [Compromise (2)](https://www.securitycentric.com.au/blog/tag/compromise)
- [data breach (3)](https://www.securitycentric.com.au/blog/tag/data-breach)
- [Essential Eight (1)](https://www.securitycentric.com.au/blog/tag/essential-eight)
- [featured (2)](https://www.securitycentric.com.au/blog/tag/featured)
- [Fundamentals (13)](https://www.securitycentric.com.au/blog/tag/fundamentals)
- [Governance (7)](https://www.securitycentric.com.au/blog/tag/governance)
- [Insider (4)](https://www.securitycentric.com.au/blog/tag/insider)
- [IRAP / ISM (1)](https://www.securitycentric.com.au/blog/tag/irap-ism)
- [managed security services (1)](https://www.securitycentric.com.au/blog/tag/managed-security-services)
- [Managed Services (2)](https://www.securitycentric.com.au/blog/tag/managed-services)
- [Penetration Test (3)](https://www.securitycentric.com.au/blog/tag/penetration-test)
- [Pentesting (5)](https://www.securitycentric.com.au/blog/tag/pentesting)
- [Phishing (6)](https://www.securitycentric.com.au/blog/tag/phishing)
- [Ransomware (5)](https://www.securitycentric.com.au/blog/tag/ransomware)
- [Red Teaming (4)](https://www.securitycentric.com.au/blog/tag/red-teaming)
- [regulations (4)](https://www.securitycentric.com.au/blog/tag/regulations)
- [Report Roundup (4)](https://www.securitycentric.com.au/blog/tag/report-roundup)
- [Risk Assessment (15)](https://www.securitycentric.com.au/blog/tag/risk-assessment)
- [risk profile (3)](https://www.securitycentric.com.au/blog/tag/risk-profile)
- [Secure Remote Work (2)](https://www.securitycentric.com.au/blog/tag/secure-remote-work)
- [Security Centric (1)](https://www.securitycentric.com.au/blog/tag/security-centric)
- [Threat Advisory (4)](https://www.securitycentric.com.au/blog/tag/threat-advisory)
- [Verizon DBIR (1)](https://www.securitycentric.com.au/blog/tag/verizon-dbir)

[More...](https://www.securitycentric.com.au/blog/wannacry-nothing-new-here-apart-from-a-catchy-name#)

- [November 2018 (4)](https://www.securitycentric.com.au/blog/archive/2018/11)
- [December 2018 (4)](https://www.securitycentric.com.au/blog/archive/2018/12)
- [April 2019 (4)](https://www.securitycentric.com.au/blog/archive/2019/04)
- [December 2021 (4)](https://www.securitycentric.com.au/blog/archive/2021/12)
- [February 2025 (4)](https://www.securitycentric.com.au/blog/archive/2025/02)
- [January 2022 (3)](https://www.securitycentric.com.au/blog/archive/2022/01)
- [May 2015 (2)](https://www.securitycentric.com.au/blog/archive/2015/05)
- [December 2020 (2)](https://www.securitycentric.com.au/blog/archive/2020/12)
- [June 2021 (2)](https://www.securitycentric.com.au/blog/archive/2021/06)
- [March 2022 (2)](https://www.securitycentric.com.au/blog/archive/2022/03)
- [April 2014 (1)](https://www.securitycentric.com.au/blog/archive/2014/04)
- [February 2016 (1)](https://www.securitycentric.com.au/blog/archive/2016/02)
- [November 2016 (1)](https://www.securitycentric.com.au/blog/archive/2016/11)
- [May 2017 (1)](https://www.securitycentric.com.au/blog/archive/2017/05)
- [September 2017 (1)](https://www.securitycentric.com.au/blog/archive/2017/09)
- [February 2018 (1)](https://www.securitycentric.com.au/blog/archive/2018/02)
- [May 2018 (1)](https://www.securitycentric.com.au/blog/archive/2018/05)
- [October 2018 (1)](https://www.securitycentric.com.au/blog/archive/2018/10)
- [March 2019 (1)](https://www.securitycentric.com.au/blog/archive/2019/03)
- [May 2019 (1)](https://www.securitycentric.com.au/blog/archive/2019/05)
- [June 2019 (1)](https://www.securitycentric.com.au/blog/archive/2019/06)
- [March 2020 (1)](https://www.securitycentric.com.au/blog/archive/2020/03)
- [April 2020 (1)](https://www.securitycentric.com.au/blog/archive/2020/04)
- [May 2020 (1)](https://www.securitycentric.com.au/blog/archive/2020/05)
- [July 2020 (1)](https://www.securitycentric.com.au/blog/archive/2020/07)
- [September 2020 (1)](https://www.securitycentric.com.au/blog/archive/2020/09)
- [November 2020 (1)](https://www.securitycentric.com.au/blog/archive/2020/11)
- [February 2021 (1)](https://www.securitycentric.com.au/blog/archive/2021/02)
- [August 2021 (1)](https://www.securitycentric.com.au/blog/archive/2021/08)
- [September 2021 (1)](https://www.securitycentric.com.au/blog/archive/2021/09)
- [February 2022 (1)](https://www.securitycentric.com.au/blog/archive/2022/02)
- [April 2022 (1)](https://www.securitycentric.com.au/blog/archive/2022/04)
- [June 2022 (1)](https://www.securitycentric.com.au/blog/archive/2022/06)
- [September 2022 (1)](https://www.securitycentric.com.au/blog/archive/2022/09)
- [November 2023 (1)](https://www.securitycentric.com.au/blog/archive/2023/11)
- [May 2024 (1)](https://www.securitycentric.com.au/blog/archive/2024/05)
- [June 2024 (1)](https://www.securitycentric.com.au/blog/archive/2024/06)
- [November 2024 (1)](https://www.securitycentric.com.au/blog/archive/2024/11)

[More...](https://www.securitycentric.com.au/blog/wannacry-nothing-new-here-apart-from-a-catchy-name#)

### Subscribe to Updates

### Security Centric

Level 34, 201 Elizabeth St  
Sydney, NSW 2000  
Call us: [+61 2 9199 0000](tel:61291990000)  
[tel:800-000-0000](tel:800-000-0000)

<https://www.facebook.com/472832472726921><https://www.instagram.com/securitycentric><https://www.linkedin.com/company/3254708><https://twitter.com/SecurityCentric>

### Contact Us

Copyright © 2020 Security Centric. All Rights Reserved.

![](https://dc.ads.linkedin.com/collect/?pid=469476&fmt=gif)