WannaCry

I can't speak as to whether the Cyber Security team saw any incidents, but I can speak to the network protections we have in place.

Maurice Moss - Firewalls https://www.youtube.com/watch?v=H3HFOlYba-4

I believe WannaCry uses the windows SMB ports to spread (139/tcp 445/tcp). We block those ports at our campus border firewalls, so no on-campus windows machine has those ports exposed to the internet.

Let's say, somehow, a windows machine on campus did get infected. We have yet more firewalls on campus dividing the campus networks up into hundreds of micro-segments, typically by campus unit. So if an unpatched machine did get infected and was on the same subnet as a bunch of other unpatched machines, the outbreak would be isolated to a few dozen machines on that same network.

Further, we recently excluded all remaining Windows XP machines from the campus academic networks. We literally shut their physical ports off if admins didn't respond to Cyber Security's requests to remove the machines from the network.

So there you go. That is, in part, the reason it's been pretty quiet around here.

/r/gatech Thread