Home / Companies / Bugcrowd / Blog / Post Details
Content Deep Dive

The Kaseya/REvil Attack Explained

Blog post from Bugcrowd

Post Details
Company
Date Published
Author
Casey Ellis
Word Count
697
Company Posts That Month
8
Language
English
Hacker News Points
-
Post removed?
No
Summary

The Kaseya Virtual System Administrator (VSA) server software, used by managed service providers (MSPs) to manage their clients, was compromised by attackers who exploited a 0-day authentication bypass vulnerability on July 2, 2021. The attackers were able to upload and execute a REvil ransomware payload, compromising up to 1 million host systems and encrypting them, causing significant disruptions to multiple large organizations. This attack highlights the risk of supply chain exploitation and the importance of prioritizing vulnerability remediation, particularly for organizations with products that form part of a broader supply chain. To mitigate this risk, Kaseya has released guidance on how to protect against the attack, including shutting down affected servers until further notice and using detection tools to identify potential indicators of compromise. Organizations can also take steps such as engaging a vulnerability management platform like Bugcrowd to quickly find and fix business-critical vulnerabilities before they are discovered by attackers.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.