A single threat actor launched the BlueKeep vulnerability from the Tor network to hide their identities. The vulnerability, tracked as CVE-2019-0708, impacts the Windows Remote Desktop Services (RDS) Microsoft has released patches for Windows 7, Server 2008, XP and Server 2003. Windows 7 and Server 2008 users can prevent unauthenticated attacks by enabling Network Level Authentication (NLA), and the threat can also be mitigated by blocking TCP port 3389. Experts at the SANS Institute observed two partial exploits that are publicly available.”]
Source: https://securityaffairs.co/wordpress/86240/hacking/internet-scan-bluekeep.html

