HomeSecurityFBI: Networks vulnerable to attacks with the end of Windows 7 support!

FBI: Networks vulnerable to attacks with end of Windows 7 support!

The FBI is warning organizations about increased security risks affecting computer network infrastructure because devices are still running Windows 7, after the operating system reached the end of its support on January 14. Specifically, the FBI said in its related announcement that it has observed that cybercriminals are targeting computer network infrastructure after an operating system has completed its “life cycle.” Thus, it pointed out that an organization’s continued use of Windows 7 can help cybercriminals gain access to its computer systems. In addition, the FBI emphasized that over time, Windows 7 becomes more vulnerable to exploits and attacks due to the lack of security updates, while many new vulnerabilities in it.

FBI

After reaching the end of support earlier this year, Windows 7 no longer receives free updates and security patches or fixes unless customers subscribe to the Extended Security Updates (ESU) program, which will allow them to receive security updates for an additional three years. The Extended Security Updates program is available for Windows 7 Professional, Windows 7 Enterprise, and Windows 7 Ultimate only through licensing programs, and does not include or provide customers with new features, user-requested non-security updates, or design change requests.


Although Microsoft claims that the free upgrade to Windows 10 from Windows 7 was only available until July 29, 2016, free upgrades to Windows 10 are still available if you follow the step-by-step Windows 10 upgrade process that includes running the Media Creation Tool and selecting “Upgrade this PC now” on computers running Windows 7.

attacks on networks

Organizations should upgrade computers running Windows 7
The FBI warns that a supported operating system is the best way to mitigate newly discovered security flaws, as it automatically receives security updates as they are released by the vendor. Although the migration process brings with it many issues, including the cost of software and hardware, these obstacles pale in comparison to the security risks organizations will face if they do not upgrade their systems.


The FBI explains that numerous system breaches have been observed in the healthcare industry due to an operating system reaching end of support. It also added that after Windows XP reached end of life on April 28, 2014, the healthcare industry saw a large increase in exposed records the following year.

Organizations that cannot immediately update Windows 7 computers with a supported operating system are advised to take the following defensive measures to protect their networks from potential attacks:


• Ensure that anti-virus, spam filters and firewalls are up to date, properly configured and secure.
• Check network configurations and isolate computer systems that cannot be updated.
• Check your network for systems using RDP, close unused RDP ports, implement two-factor authentication (2FA) where possible and log RDP connection attempts.

Windows 7

Windows 7 Flaws Exploited by Previous Attacks
A number of vulnerabilities affecting Windows 7 that were patched by Microsofthave been used by threat actors in attacks targeting vulnerable devices connected to the Internet. Among them, the FBI cited the critical BlueKeep remote code execution (RCE) affecting the Windows Remote Desktop Services (RDS) platform, which was fixed by Microsoft in May 2019. It also pointed to the WannaCry ransomware that used the ETERNALBLUE exploit and the DOUBLEPULSAR Windows kernel Ring-0 exploit to spread and infect more than 57,000 devices worldwide in 2017.


Microsoft patched the vulnerability exploited by ETERNALBLUE in March 2017, but that did not stop the attacks because Windows 7 users failed to update their systems in a timely manner, and subsequently, 98% of systems infected with WannaCry used Windows 7-based operating systems. Finally, since few have the ability to maintain a patched Windows 7 system after its support ends, cybercriminals will continue to see Windows 7 as an “easy” target.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS