WannaCry: the worm that punished skipped updates
Hospitals, a ransom screen, a patch that was already sitting there. Install it.
WannaCry showed up in May 2017 like a loud flu. Machines displayed a ransom note. It spread itself across networks that still had a Windows hole related to file sharing. The NSA had known about that class of bug. A leak dumped the idea into the world. Microsoft had shipped a patch. Many offices had not installed it. Hospitals in the UK were among the places that went down. A kill switch in the worm’s code got pulled almost by accident when a researcher registered a domain the malware checked. That slowed it. It did not unencrypt the disks that had already gone.
What a home user should hear
You are not a hospital trust. You still run Windows. You still postpone updates because a restart is annoying. WannaCry was a mass event because the unpaid patch sat on millions of boxes at once. The next worm will use a different hole. The unpaid patch is the constant.
Ransomware that does not worm still arrives as a file or a remote tool. The display is the same family: pay us in crypto, timer, panic. Paying funds the next round. Restoring from a copy you control is the adult exit.
Networks that share too much
WannaCry jumped between computers that could see each other. Home WiFi with file sharing on, an old PC that never updates, and a laptop with tax files is a tiny version of that hospital network. Turn off sharing you do not use. Keep one machine from being the petri dish for the others.
A worm from 2017 is history. Unpatched software is not. That is the awareness. Install the update. Keep a backup that is not plugged in all day. Do not let a pop up become remote control. The note on the screen is the last chapter, not the first.