Free Republic
Browse · Search
News/Activism
Topics · Post Article

Skip to comments.

Latest ransomware attack appears to hit hundreds of American businesses (incident at the Miami-based IT firm Kaseya)
The Guardian ^ | 7-2-21 | Guardian staff

Posted on 07/02/2021 5:44:10 PM PDT by dynachrome

Hundreds of American businesses have been hit by a ransomware attack ahead of the Fourth of July holiday weekend, according to the cybersecurity company Huntress Labs.

Huntress Labs said on Friday that 200 American businesses were hit after an incident at the Miami-based IT firm Kaseya, potentially marking the latest in a line of hacks destabilizing US companies.

“This is a colossal and devastating supply chain attack,” John Hammond, a senior security researcher with Huntress, said in an email, referring to an increasingly high profile hacker technique of hijacking one piece of software to compromise hundreds or thousands of users at a time.

Hammond added that because Kaseya is plugged in to everything from large enterprises to small companies “it has the potential to spread to any size or scale business.”

Kaseya, in a statement posted on its own website, said it was investigating a “potential attack” on VSA, a widely used tool to reach into corporate networks across the United States.

In the statement, Kaseya said the tool offers to monitor and manage servers, desktops, network devices and printers and that it may have been attacked. Such an attack can be particularly insidious to address, said Chris Grove, a security expert at the cybersecurity firm Nozomi Networks.

(Excerpt) Read more at theguardian.com ...


TOPICS: Business/Economy; Crime/Corruption; News/Current Events; US: Florida
KEYWORDS: florida; hack; kaseya; monerocrypto; ransomware
This could be ugly. Extent unknown until you return to work on Monday and turn the 'puter on.
1 posted on 07/02/2021 5:44:10 PM PDT by dynachrome
[ Post Reply | Private Reply | View Replies]

To: dynachrome

It is a conspiracy theory that China would have anything to do with this all you insurrectionists!


2 posted on 07/02/2021 5:45:24 PM PDT by E. Pluribus Unum ("Communism is not love. Communism is a hammer which we use to crush the enemy." ― Mao Tse-tung)
[ Post Reply | Private Reply | To 1 | View Replies]

To: dynachrome

I take it this company wasn’t on the ‘hands-off’ list Biden gave to Putin??


3 posted on 07/02/2021 5:47:27 PM PDT by Spirit of Liberty (Idiots are of two kinds: those who try to be smart and those who think they are smart.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: dynachrome

It’s gonna get real ugly soon.

L


4 posted on 07/02/2021 5:48:46 PM PDT by Lurker (Peaceful coexistence with the Left is not possible. Stop pretending that it is. )
[ Post Reply | Private Reply | To 1 | View Replies]

To: dynachrome

“Kaseya has 40,000 customers for its products, though not all use the affected tool.”

And who are they?


5 posted on 07/02/2021 5:49:31 PM PDT by dynachrome ("I will not be reconstructed, and I do not give a damn.")
[ Post Reply | Private Reply | To 1 | View Replies]

To: dynachrome

In remembrance to the movie Independence Day: nuke the bastards


6 posted on 07/02/2021 5:55:35 PM PDT by Mouton (The enemy of the people is the media.)
[ Post Reply | Private Reply | To 5 | View Replies]

To: dynachrome

Two days ago a friend’s company was hit. He said it was probably Conti and it came from the Russians. Apparently they paid the ransom.


7 posted on 07/02/2021 5:57:33 PM PDT by pbear8 (the Lord is my light and my salvation)
[ Post Reply | Private Reply | To 1 | View Replies]

To: dynachrome

Spatula City
Mel’s Char Palace
Mainway Enterprises...


8 posted on 07/02/2021 6:02:43 PM PDT by Army Air Corps (Four Fried Chickens and a Coke)
[ Post Reply | Private Reply | To 5 | View Replies]

To: dynachrome

There is a company called “recyber.net” with their site hosted in Panama and supposedly based in the Netherlands who has been banging on most of the firewalls in the USA trying to get in.

This could be one of them.


9 posted on 07/02/2021 6:36:38 PM PDT by Zathras
[ Post Reply | Private Reply | To 1 | View Replies]

To: dynachrome
What's the problem here.

I assume none of these business are on Biden's critical list of 16.

So what's the problem ¿

10 posted on 07/02/2021 7:07:51 PM PDT by FreeReign
[ Post Reply | Private Reply | To 1 | View Replies]

To: dynachrome

........ Well ... These companies are fair game because they weren’t on Biden’t Don’t Hack List ......


11 posted on 07/02/2021 7:09:54 PM PDT by R_Kangel ("A nation of sheep will beget a nation ruled by wolves")
[ Post Reply | Private Reply | To 1 | View Replies]

To: Lurker

Thing is, you can never, ever trust these outfits again. I’ve been a longtime user of SolarWinds products, but never again. Kaseya sure wanted my business back in the day, but SolarWinds Orion was there first. Glad I wasn’t around when it hit the shitter.


12 posted on 07/02/2021 7:11:36 PM PDT by Noumenon (The Second Amendment exists primarily to deal with those who just won't take no for an answer. KTF)
[ Post Reply | Private Reply | To 4 | View Replies]

To: Noumenon

We use Huntress.

L


13 posted on 07/02/2021 8:19:56 PM PDT by Lurker (Peaceful coexistence with the Left is not possible. Stop pretending that it is. )
[ Post Reply | Private Reply | To 12 | View Replies]

To: Lurker

I’ll check that out. Thanks for the tip!


14 posted on 07/02/2021 8:35:34 PM PDT by Noumenon (The Second Amendment exists primarily to deal with those who just won't take no for an answer. KTF)
[ Post Reply | Private Reply | To 13 | View Replies]

To: Noumenon

Agreed. These cloud based monitoring services will never be used by us. Just too much information they require such as SNMPv3 credentials, ssh credentials, device IPs, etc.

A company who wants to manage their AV gear on our network wants to use -their- MFA solution, I said no and hell no - you will use our MFA solution. They have rolled out the “you’re the first customer that won’t let us use our MFA solution” claim. If that’s true, I’m shocked, as how can you control or monitor their access into your network?

Contractor access into networks is getting exploited as of late. We try to keep that locked down as much as possible.


15 posted on 07/02/2021 8:47:02 PM PDT by Fury
[ Post Reply | Private Reply | To 12 | View Replies]

To: Fury

I had the same issue with a security company who contracted to monitor the cams we set up at the Yakima Oldcastle yards. My response was similar to yours: NFW. To make this work, I set up a parallel net that I isolated on selected switch and router ports.


16 posted on 07/02/2021 9:15:41 PM PDT by Noumenon (The Second Amendment exists primarily to deal with those who just won't take no for an answer. KTF)
[ Post Reply | Private Reply | To 15 | View Replies]

To: All

This will probably be the second time my company was hit by ransomware in 11 months and the first one nearly killed the company. Our moronic IT team should have been dropped last October, when we recovered last year but they were kept around.


17 posted on 07/03/2021 11:33:56 AM PDT by newnhdad (Our new motto: USA, it was fun while it lasted.)
[ Post Reply | Private Reply | To 16 | View Replies]

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
News/Activism
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson