Cyber Range Crypto Attack Incident Response
Since joining the cyber range community just a week ago, there has already been a security incident where linux virtual machines have been compromised. This is due to machines using the same default credential "labuser:Cyberlab123!". Below is the official notice from Azure. Since the purpose of the Cyber Range is to simulate a real world corporate network environment, we still want to allow inbound attacks. However, to prevent accidentally or intentionally attacking assets outside the Cyber Range, the following Network Security Group was implemented to block the most common OUTBOUND traffic for ports such as SSH, RDP, SMB and other known crypto miner ports.

Since joining the cyber range community just a week ago, there has already been a security incident where linux virtual machines have been compromised. This is due to machines using the same default credential "labuser:Cyberlab123!".
Below is the official notice from Azure.
Since the purpose of the Cyber Range is to simulate a real world corporate network environment, we still want to allow inbound attacks.
However, to prevent accidentally or intentionally attacking assets outside the Cyber Range, the following Network Security Group was implemented to block the most common OUTBOUND traffic for ports such as SSH, RDP, SMB and other known crypto miner ports.