Last week, members of the notorious Shadow Brokers group leaked a series of hacking tools allegedly belonging to the NSA that can be used to compromise any Windows system.
A few days after the leak, Microsoft rushed to reassure users, assuring them that security updates have already been released for all exploited vulnerabilities. However, the existence of such updates does not necessarily mean that Windows users are safe if they do not proceed – as is inevitable – to install them.
According to The Register, this did not happen, and thousands of computers were infected with malware, with the number constantly increasing.
As researchers report, the main exploit used to compromise systems is ETERNALBLUE, which uses the DOUBLEPULSAR backdoor to infect computers.
So far, approximately 15,000 systems infected with DOUBLEPULSAR have been discovered, while researchers estimate that the actual number is at least three times higher.
What's worse is that the vulnerability that hackers are now trying to exploit was patched by Microsoft in March of this year, which means that the compromised systems were not updated. On the other hand, it should be noted that the patch in question is intended for systems with Windows Vista SP2 and later versions, so users of older operating systems that are no longer supported (such as Windows XP) are literally "in the air".
All other users should update their computers as soon as possible.
"This security update resolves vulnerabilities in Microsoft Windows. The most critical of these could allow remote code execution if an attacker sends specially crafted messages to a Microsoft Server Message Block 1.0 (SMBv1) server," Microsoft explains.
The largest percentage of infected computers is located in the United States, while their number is very likely to increase in the coming days.


