UK hospital meltdown after ransomware worm uses NSA vuln to raid IT

No, it looks like it came from an internal network accessed by a VPN by a supplier employee who was infected by a colleague who almost certainly clicked on something from the Internet.

I'm thinking he probably airlock switched his infected local PC from his corporate LAN to the supplier LAN to do some work.

