{"id":23596,"date":"2017-04-14T17:11:47","date_gmt":"2017-04-14T22:11:47","guid":{"rendered":"http:\/\/olduvai.ca\/?p=23596"},"modified":"2017-09-30T13:07:43","modified_gmt":"2017-09-30T18:07:43","slug":"leaked-nsa-malware-threatens-windows-users-around-the-world","status":"publish","type":"post","link":"https:\/\/olduvai.ca\/?p=23596","title":{"rendered":"Leaked NSA Malware Threatens Windows Users Around the World"},"content":{"rendered":"<div class=\"Post-header\" data-reactid=\".ti.1.0.0\">\n<div class=\"Post-header-grid\" data-reactid=\".ti.1.0.0.2\">\n<div class=\"Post-header-row\" data-reactid=\".ti.1.0.0.2.0\">\n<div class=\"Post-header-block\" data-reactid=\".ti.1.0.0.2.0.1\">\n<div data-reactid=\".ti.1.0.0.2.0.1.0\">\n<div class=\"Post-title-block\" data-reactid=\".ti.1.0.0.2.0.1.0.1\">\n<h3 class=\"Post-title\" data-reactid=\".ti.1.0.0.2.0.1.0.1.0\"><a class=\"Post-title-link\" href=\"https:\/\/theintercept.com\/2017\/04\/14\/leaked-nsa-malware-threatens-windows-users-around-the-world\/\" data-reactid=\".ti.1.0.0.2.0.1.0.1.0.0\">LEAKED NSA MALWARE THREATENS WINDOWS USERS AROUND THE WORLD<\/a><\/h3>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<div class=\"Post-body\" data-reactid=\".ti.1.0.1\">\n<div class=\"Post-content-block-outer\" data-reactid=\".ti.1.0.1.2\">\n<div class=\"GridContainer Post-scroll-container\" data-reactid=\".ti.1.0.1.2.0\">\n<div class=\"GridRow\" data-reactid=\".ti.1.0.1.2.0.0\">\n<div class=\"Post-content-block\" data-reactid=\".ti.1.0.1.2.0.0.1\">\n<div class=\"Post-content-block-inner\" data-reactid=\".ti.1.0.1.2.0.0.1.0\">\n<div class=\"PostContent\" data-reactid=\".ti.1.0.1.2.0.0.1.0.4\">\n<div data-reactid=\".ti.1.0.1.2.0.0.1.0.4.1:$p-0\">\n<p>The ShadowBrokers, an entity <a href=\"https:\/\/theintercept.com\/2016\/08\/19\/the-nsa-was-hacked-snowden-documents-confirm\/\">previously confirmed by The Intercept to have leaked authentic malware<\/a> used by the NSA to attack\u00a0computers around the world, today released another cache of what appears to be extremely potent (and previously unknown) software capable of breaking into systems running Windows. The software could give nearly anyone with sufficient technical knowledge the ability to wreak havoc on millions of Microsoft users.<\/p>\n<p>The leak includes a litany of typically codenamed software \u201cimplants\u201d with names like ODDJOB, ZIPPYBEER, and ESTEEMAUDIT, capable of breaking into \u2014 and in some cases seizing control of \u2014 computers running version of the Windows operating system earlier than the most recent Windows 10. The vulnerable Windows versions ran more than 65 percent of desktop computers surfing the web last month, according to <a href=\"https:\/\/www.netmarketshare.com\/operating-system-market-share.aspx?qprid=10&amp;qpcustomd=0\">estimates<\/a> from the tracking firm Net Market Share.<\/p>\n<p>The crown jewel of the implant collection appears to be a program named FUZZBUNCH, which essentially automates\u00a0the deployment of NSA malware, and would allow a member of agency\u2019s Tailored Access Operations group to more easily infect a target from their desk.<\/p>\n<div class=\"img-wrap align-center width-fixed\"><a href=\"https:\/\/prod01-cdn07.cdn.firstlook.org\/wp-uploads\/sites\/1\/2017\/04\/2008-1492192653.jpg\"><img decoding=\"async\" class=\"aligncenter size-article-medium wp-image-122766\" src=\"https:\/\/prod01-cdn07.cdn.firstlook.org\/wp-uploads\/sites\/1\/2017\/04\/2008-1492192653-540x394.jpg\" alt=\"\" \/><\/a><\/p>\n<p class=\"caption\">via Matthew Hickey<\/p>\n<\/div>\n<p>According to security researcher and hacker Matthew Hickey, co-founder of <a href=\"https:\/\/www.myhackerhouse.com\/\">Hacker House<\/a>, the significance of what\u2019s now publicly available, including \u201czero day\u201d attacks on previously undisclosed vulnerabilities, cannot be understated: \u201cI don\u2019t think I have ever seen so much exploits and 0day [exploits] released at one time in my entire life,\u201d he told The Intercept via Twitter DM, \u201cand I have been involved in computer hacking and security for 20 years.\u201d Affected computers will remain vulnerable until Microsoft releases patches for the zero-day vulnerabilities and, more crucially, until their owners then apply those patches.<\/p>\n<p>&#8230;click on the above link to read the rest of the article&#8230;<\/p>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>LEAKED NSA MALWARE THREATENS WINDOWS USERS AROUND THE WORLD The ShadowBrokers, an entity previously confirmed by The Intercept to have leaked authentic malware used by the NSA to attack\u00a0computers around the world, today released another cache of what appears to be extremely potent (and previously unknown) software capable of breaking into systems running Windows. The [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0,"footnotes":""},"categories":[6],"tags":[1401,551,577,15125,5567],"class_list":["post-23596","post","type-post","status-publish","format-standard","hentry","category-liberty","tag-malware","tag-national-security-agency","tag-nsa","tag-sam-biddle","tag-the-intercept"],"_links":{"self":[{"href":"https:\/\/olduvai.ca\/index.php?rest_route=\/wp\/v2\/posts\/23596","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/olduvai.ca\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/olduvai.ca\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/olduvai.ca\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/olduvai.ca\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=23596"}],"version-history":[{"count":1,"href":"https:\/\/olduvai.ca\/index.php?rest_route=\/wp\/v2\/posts\/23596\/revisions"}],"predecessor-version":[{"id":23597,"href":"https:\/\/olduvai.ca\/index.php?rest_route=\/wp\/v2\/posts\/23596\/revisions\/23597"}],"wp:attachment":[{"href":"https:\/\/olduvai.ca\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=23596"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/olduvai.ca\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=23596"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/olduvai.ca\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=23596"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}