President Biden says he has directed US intelligence agencies to investigate the Kaseya ransomware attack and adds “we're not certain” who is behind the attack
The Kaseya inquiry arrived amid a widening U.S. ransomware response: the FBI had already said it was investigating roughly 100 ransomware variants, many with links to Russia. The administration had also attributed the SolarWinds operation to Russia while saying it was executed from within the U.S.
U.S. intelligence agencies are tasked with establishing responsibility for the Kaseya attack, while Biden publicly avoids assigning blame before that assessment is complete.
Kaseya faces sharper scrutiny of its vulnerability-reporting and remediation process after the reported prior warning about an exploited flaw.
Second-order effects
The attribution process gives the Biden administration the evidentiary basis for its subsequent warning to Putin, tying ransomware response more directly to U.S.-Russia relations.
Security researchers’ disclosure practices become more consequential for software vendors as prior reports of flaws can become central to post-incident accountability.
Third-order effects
Repeated ransomware incidents are pushing U.S. cyber policy toward treating major attacks as a national-security and diplomatic problem, not solely an FBI-led criminal investigation.
If this pattern persists, vendors’ handling of reported vulnerabilities will be judged alongside attacker attribution in the public response to major breaches.
The trend: Ransomware is being elevated from an enterprise-security risk to a test of coordinated U.S. intelligence, law-enforcement, and diplomatic response.
“Although the scale of this incident may make it so that we are unable to respond to each victim individually, all information we receive will be useful in countering this threat.” 👀 https://twitter.com/...
During the last 48 hours, the number of Kaseya VSA instances that are reachable from the internet has dropped from over 2.200 to less than 140 in our last scan today. https://csirt.divd.nl/...
#ESETresearch responded to ransomware deployed as supply-chain attack against #Kaseya VSA users attributed to #REvil beginning Friday afternoon EDT (US)/evening CEST (Europe). Detection was added for Win32/Filecoder.Sodinokibi.N on Friday shortly after.https://www.welivesecurity.…
.@CISAgov and @FBI strongly recommend MSPs and #MSP customers affected by the Kaseya VSA supply-chain #ransomware attack take immediate action. See https://us-cert.cisa.gov/... for recommendations. #Cybersecurity #InfoSec #Ransomware
Updates Regarding VSA Security Incident July 4, 2021 - 10:00 AM EDT Next Update will be published July 4, 2021, in the early afternoon EDT https://www.kaseya.com/...
If you haven't seen it, Kaseya has now shared their own detection tool. From their report, “The new Compromise Detection Tool was rolled out last night to almost 900 customers who requested the tool.” https://helpdesk.kaseya.com/ ...
Some small respite for victims of the Kaseya attack - “REvil representatives have told victims that they only encrypted networks, and nothing more. This means that REvil likely did not steal any of the victims' data” https://www.bleepingcomputer.com/ ... #ransomware #malware #cyb…
@FBI The vendor says, “Only a very small percentage of our customers were affected - currently estimated at fewer than 40 worldwide.” The FBI says, “Although the scale of this incident may make it so that we are unable to respond to each victim individually.” 🤔
President Joe Biden said he has directed U.S. intelligence agencies to investigate who was behind a sophisticated ransomware attack that hit hundreds of American businesses and led to suspicions of Russian gang involvement. https://www.reuters.com/...