Hacker Newsnew | past | comments | ask | show | jobs | submitlogin
Updates Regarding VSA Security Incident (kaseya.com)
1 point by collinmanderson on July 6, 2021 | hide | past | favorite | 1 comment


> Kaseya’s VSA product has unfortunately been the victim of a sophisticated cyberattack. Due to our teams’ fast response, we believe that this has been localized to a very small number of on-premises customers only.

Great job patting yourselves on the back, 9 times... I love how they mention how its sophisticated, localized and quick they were to detect it. Then they drop the details, which are literally the opposite of what they say... it impacted 1500+ businesses, the attackers got in via command injection, they only caught it after customers started complaining.

If you look at the OWASP top 10, they basically ticked 6/10 of the boxes (A1, A2, A3, A5, A8 A10).




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: