What would you do if a hacker had access to all of your sensitive documents and data through a machine that they had exploited, with access to control your webcam as well as monitor the screen and keyboard?

It’s not something out of action movie, what we’re describing is Eternal Blue, a cyber attack that preys on businesses not updating their systems.

Whilst this cyber attack can essentially immobilise a business, it’s avoidable through basic cyber security practices.

In our latest blog post to raise awareness about the dangers of cyber attacks, we’re taking a look at Eternal Blue, the damage it can do and how you can prevent your business from being affected.

Watch the Eternal Blue Video

Read Video Transcript

Behind the Hack – EternalBlue – Time to Update

We’re all guilty of not updating our devices, systems and software.

When we’re busy working hard in the business, it’s easier and quicker to just ‘put it off’, but right now we can exclusively reveal, thanks to our ethical hacker, the devastating effect using out of date and non-updated technology can have on your business.

It happens every day…we’re made aware of available updates but even if it’s labelled “critical” we think: ‘what’s the worse that can happen?’ Well, we can show you from our hackers’ point of view.

Even in today’s modern world, as soon as a new system, service or piece of software is created, there are people looking for ways to hack it.  Right now you’re looking at ‘EternalBlue’, developed to exploit a vulnerability in some versions of Microsoft products. 
The updates your computer tells you about contains vital patches to secure these vulnerabilities as soon as they’re discovered. 
In this case here’s an older version of a Windows server that hasn’t yet been updated.  Our hacker uses some special monitoring software to identify the target machine, establish a connection by linking IP addresses and ports, then with a simple command, view all the private credentials used to access the network

Our hacker can then do whatever they want; launch a further attack, steal and lock your data, run some code to monitor your screen, even detect keystrokes or spy on you and your staff with your webcam.

All businesses rely so much on technology these days, so talk to us about how you can be better protected without having to do the work yourself.

What Is Eternal Blue?

External Blue is an exploit that was created by the US National Security Agency which targets a vulnerability in Windows machines. In 2017, a hacking group were able to access and leak Eternal Blue as part of an attack on the NSA.

Whilst a patch was released by Microsoft one month after the leak, many system administrators did not update, leaving their machines vulnerable to the exploit.

In May 2017, Eternal Blue exploit was used to spread the infamous WannaCry ransomware that went on to infect over 230,000 Windows PCs in a single day, entire businesses were crippled and notable organisations such as the NHS were severely impacted. 

How Does It Work?

With specialist monitoring software, a hacker can identify machines that have not been updated and are therefore vulnerable to Eternal Blue.

After establishing a connection by linking IP addresses and ports, the hacker can use a single command to gain complete unobstructed access to the device and all of the files it contains.

With access to your machine, a hacker can carry out further attacks, view your private credentials, steal and lock data, and even run code that allows them to monitor your screen, see your keystrokes and, perhaps most disturbing, spy on you through your webcam.

How To Prevent Eternal Blue Attacks

In the case of Eternal Blue, preventing your machine from being exploited means ensuring you have the most recent updates installed on the machine.

Whilst it can be easier to put them off, these updates contain vital patches to secure vulnerabilities as soon as they are discovered.

If you are struggling to stay on top of updates or are finding they impact efficiency, consider using a dedicated cyber security provider who can update your machines out of hours on a regular basis to ensure they are protected. 

Protect Your Business with Absolutely PC

Is your business keeping all machines and software up to date with the latest updates? If not, you could be leaving yourself at risk of the devastating impacts of Eternal Blue and similar attacks. 

To find out more about protecting your business against all forms of cyber attack, call us today on 0117 975 9523 or fill out a contact form and we will get back to you.

 

When Cybercriminals Turn On Each Other, Your Firm Still Loses

When cybercriminals start threatening each other, it can look like good news, even an opportunity. But for a regulated firm, trusting one attacker to rescue you from another is a governance risk, not a lifeline. Here is why the only reliable route through a cyber incident runs through proper protection and trusted support, and how to make sure your firm is ready before the pressure hits.

The Fake CAPTCHA Trap: “Prove You’re Human” With Fresh Suspicion

CAPTCHAs are so familiar that we barely register them, and that trust is exactly what criminals are now exploiting. A new breed of fake verification page asks you to “prove you’re human” by sending a text, quietly racking up premium-rate charges that only surface later. For regulated firms, the stakes reach further than the bill. Here’s how the trap works, and how to protect your team.

Why a Routine Update Has Become a Board-Level Risk

For regulated firms, a routine software update should never become a compliance incident. Yet a highly convincing fake Windows 11 update is now fooling even experienced professionals, and a single click can expose client data. This post explains how the scam works, why it slips past security tools, and the governance-led steps every professional firm should take to stay protected and audit-ready.

Fake Microsoft Azure Alerts, Why Regulated Firms Must Not Let Their Guard Down

A sophisticated new phishing campaign is exploiting Microsoft Azure Monitor to deliver scam alerts that look entirely legitimate. For regulated firms, where client trust and data governance are non-negotiable, this evolving threat demands a more rigorous approach to email verification and incident response.

Is Your Data Security Keeping Pace With Your Business?

Most professional service firms believe their data security is under control — but confidence and compliance readiness are not the same thing. As cloud platforms, legacy systems and AI tools increase complexity beneath the surface, the gap between perceived security and actual governance grows. This post examines the questions every regulated firm should be asking about where data lives, who has access, and whether the answers would satisfy an auditor.

Why AI is the wrong tool for Passwords

Are the passwords protecting your business as strong as you think they are? AI may seem like a smart shortcut, but when it comes to security, it could be creating hidden weaknesses you can’t afford to ignore.

Beware the Next Generation of Phishing Attacks

Phishing scams are no longer crude or easy to spot. New, smarter attacks are changing the rules — and businesses need to rethink how they stay protected.

Your Browser Knows More Than You Think

Your browser doesn’t just see the websites you visit. It sees patterns, habits, and clues about your business. Most people never check what’s being shared behind the scenes. That’s a risk worth paying attention to.

Old Passwords Are Still Unlocking Systems

Old passwords your team hasn’t used in years could still unlock your systems — and attackers know it. A recent cyber incident revealed how forgotten credentials put professional service firms at serious risk, and why enforcing MFA has never been more important.

Protecting Your Business from Today’s Smarter Digital Fraud

Digital fraud is evolving at a rapid pace, and modern scams are becoming harder to spot than ever. In this article, we explore practical, everyday habits your team can adopt to stay safer online — and how a few simple tools can make a big difference.

Beware the Next Generation of Phishing Attacks

Phishing scams are no longer crude or easy to spot. New, smarter attacks are changing the rules — and businesses need to rethink how they stay protected.

Windows 10 Extended Security Update

Windows 10 End of Life is in October 2025 but Microsoft is now allowing the purchase of an Extended Security Update. With different options for businesses and individuals this article looks at what is included in the program and likely costs for subscription.

WordPress Security – Attacks leave 1.6 million sites damaged

Are you confident that your WordPress website is secure? Yesterday, on the 9th of December 2021, 1.6 Million WordPress Sites were Hit With 13.7 Million Attacks In 36 Hours From 16,000 IPs. It’s safe to say this is a major concern to businesses everywhere. WordPress...

Why AI is the wrong tool for Passwords

Are the passwords protecting your business as strong as you think they are? AI may seem like a smart shortcut, but when it comes to security, it could be creating hidden weaknesses you can’t afford to ignore.

IT Security: Folina Vulnerability Fixed

IT security update: Folina vulnerability has been fixed by Microsoft. How to ensure your system is protected and reverse the temporary fix we suggested.

New Dark Web Monitoring Tool Available from Absolutely PC

How much of your business and personal data is available online? The results could surprise you. With small business in the UK alone targeted by up to 65,000 attempted cyber attacks per day, data breaches and leaks are becoming an increasingly common occurrence. Once...

Business IT Security – Using 2FA

Business IT security is often about doing the basics really well, like securing your accounts using 2FA. In this post find out why 2FA helps to keep your business cyber secure

8.4 Billion Passwords Leaked In “RockYou2021” Hack – How To Protect Your Business

The largest password collection of all time was recently leaked onto a hacker forum, with an eye-watering 8,459,060,239 (8.4 billion) unique entries stored in a 100GB TXT file putting potentially billions of logins at risk.  Dubbed as ‘RockYou2021’ after the RockYou...

Protecting Your Business from Today’s Smarter Digital Fraud

Digital fraud is evolving at a rapid pace, and modern scams are becoming harder to spot than ever. In this article, we explore practical, everyday habits your team can adopt to stay safer online — and how a few simple tools can make a big difference.

Another Cyber Security zero-day exploit

On 9th November Microsoft released a fix for Windows based computers that allowed an attacker to take control of your systems as an admin.  This was known as CVE-2021-41379 and was the latest in a series of cyber security issues involving Elevation of Privilege...