Kaseya VSA Supply-Chain Attack
2021-07-02 09:00:00 Author: www.trustwave.com(查看原文) 阅读量:75 收藏

On the afternoon of Friday, July 2, reports indicated that the REvil ransomware gang is actively targeting managed services providers (MSPs) via a Kaseya VSA supply-chain attack.

Kaseya VSA is a cloud-based MSP platform that allows providers to perform patch management and client monitoring for their customers. According to the July 2nd security advisory from Kaseya, the company recommends that Kaseya VSA users immediately shut down any VSA server until further instructions are given by the vendor. “It’s critical that you do this immediately because one of the first things the attacker does is shut off administrative access to the VSA.”

Trustwave does not use the Kaseya VSA platform. At this time, there is no evidence or reason to believe that the Kaseya supply-chain attack has impacted Trustwave itself.

Trustwave is diligently working with its customers and partners to further determine any impact.

If you believe you may have been compromised, please get in touch with the Trustwave Digital Forensics and Incident Response (DFIR) team or your Trustwave support point of contact.

Trustwave will be updating this post with additional pertinent information as it becomes available.


文章来源: https://www.trustwave.com/en-us/resources/blogs/trustwave-blog/kaseya-vsa-supply-chain-attack/
如有侵权请联系:admin#unsafe.sh