UK hospital meltdown after ransomware worm uses NSA vuln to raid IT


Can't believe any network would allow users to run stuff from %temp%...

It's just one of the things a network admin can do which helps lock the system down. From what I've seen (on a VM used for the purpose), malware from emails / web browsers invariably tries to run an EXE from the temp directory.

