, 5 tweets, 1 min read Read on Twitter
There's two sides to this. There's a "just patch" religiosity that ignores the practical difficulties of patching. On the other hand, it's been over 15 years since you learned that you shouldn't be putting systems on the network that are difficult to patch.
You can't patch that medical device with RDP exposed, and frankly, you can't even scan the network for fear of crashing medical devices. I understand that. My question is why the hell you've been buying medical devices for the past 15 years that can't be patched or scanned.
In any case, your chief threat from an RDP worm isn't unpatched RDP so much as mimikatz/psexec infecting patched system that aren't even running RDP in the first place. That's the lesson notPetya taught us.
If you are a typical organization, you patched 90% of vulnerable RDP systems, and the remaining systems you probably don't care about, like decommissioned VMs that are still running that you haven't bothered to turn off.
But that old VM has a domain admin logged in, so once it's credentials are stolen, all computers in the domain are infected, moving on to other domains with trust relationships, and now your employees get a free month's vacation as you attempt to restore your business.
Missing some Tweet in this thread?
You can try to force a refresh.

Like this thread? Get email updates or save it to PDF!

Subscribe to Robᵇᵉᵗᵒ Graham
Profile picture

Get real-time email alerts when new unrolls are available from this author!

This content may be removed anytime!

Twitter may remove this content at anytime, convert it as a PDF, save and print for later use!

Try unrolling a thread yourself!

how to unroll video

1) Follow Thread Reader App on Twitter so you can easily mention us!

2) Go to a Twitter thread (series of Tweets by the same owner) and mention us with a keyword "unroll" @threadreaderapp unroll

You can practice here first or read more on our help page!

Follow Us on Twitter!

Did Thread Reader help you today?

Support us! We are indie developers!


This site is made by just three indie developers on a laptop doing marketing, support and development! Read more about the story.

Become a Premium Member ($3.00/month or $30.00/year) and get exclusive features!

Become Premium

Too expensive? Make a small donation by buying us coffee ($5) or help with server cost ($10)

Donate via Paypal Become our Patreon

Thank you for your support!