meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Monday, July 5th, 2021

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News, Technology

4.9696 Ratings

🗓️ 4 July 2021

⏱️ 5 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Special Podcast: Kaseya VSA REvil Ransomware Incident

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Monday, July 5th, 2021 edition of the Sansonet Storms Centers.

0:06.2

Stormcast, my name is Johannes Ulrich, and today I'm recording from Jacksonville, Florida.

0:12.9

Now, I mentioned that I wasn't going to produce a podcast for Monday, but given the Kasea incident that broke on Friday, I figured I'll

0:26.6

push out this podcast to sort of give you a quick summary of what's going on here.

0:33.0

First of all, Kasea is a software that's typically used by managed service providers, MSPs, that manage

0:39.6

networks of typically small and medium-sized companies.

0:45.7

Part of a Kasea solution is Kasea VSA, which also includes a patch management component

0:53.7

that these managed service providers can use to

0:57.0

basically push out patches in a control manner to their client.

1:02.0

The problem was that on Friday, apparently, the R. Evil Ransomber was propagating via

1:10.0

Kasea VSA. So the problem here is a little bit sort of a two-layer

1:14.1

supply chain attack. Cassaya was apparently compromised, managed service providers that used

1:21.3

Kasea's product, then picked up the ransomware and pushed it to their clients.

1:28.3

As an affected victim, you are essentially a customer of a managed service provider that

1:35.3

does use Kaseya VSA to manage your network.

1:40.3

Kaseya does claim 40,000 customers. Now, we have heard numbers of around 200 or so companies that say they are affected by this.

1:53.1

But remember that a Kasea customer is usually an MSP, and then these MSPs, of course, have multiple businesses whose network they are managing.

2:03.4

So I suspect as people get back to work on Tuesday, probably in the United States,

2:08.9

given the 4th of July weekend that many of them will find an infection with the R.Eval

2:16.7

ransomware. If you are a customer of an MSP that uses

2:22.6

Kasea, then definitely get in touch with the MSP. If you are a Kasea customer, then get in touch

2:31.8

with Kasea.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2025.