3 ms·
And apparently one of the vulnerabilities exploited in this attack had been discovered and reported to Kaseya by independent researchers back in April: https://
by terom 5y ago
And apparently one of the vulnerabilities exploited in this attack had been discovered and reported to Kaseya by independent researchers back in April: https://news.ycombinator.com/item?id=27763202 https://news.ycombinator.com/item?id=27763202
- cartoonworld 5y agoKaseya doesn't have a CISO from what I can see. CEO Fred Voccola retreived from https://blog.malwarebytes.com/ransomware/2021/07/kaseya-ceo-the-impact-of-this-incredibly-sophisticated-attack-is-very-minimal/ https://blog.malwarebytes.com/ransomware/2021/07/kaseya-ceo-... We weren’t quite sure exactly what it was, but as third parties, the community, our own monitoring customers, we started noticing some strange behaviors,” Voccola recounted in the video. “Within an hour, we immediately shut down VSA.” [...] “When something happens, it’s how prepared the organization was, how quickly the organization is to admit something happened,” Voccola said. “Seek help from people and try to get focus on the customers and get information out there.” That makes sense though, their leadership is laser-focused on successful outcomes and a commitment to their customers. It was their incompetent acquisition culture who cut corners on all the boring stuff, like validation, testing, assurance, quality, engagement with for-free security researchers. Their plan was to stumble into the dashboard and trip over the off switch, after someone else told them they'd been wrecked. This is absurd, incompetent, immorally negligent and contrary to industry SOPs (use bug bounties, have a CISO).