A Dutch security researcher group says it had notified Kaseya in April about one of the flaws that was exploited in the devastating ransomware attack last week
President Biden is meeting officials to discuss recent attacks, including latest affecting hundreds of organizations around the world
Wall Street Journal
Context & Ripple Effects
The disclosure that Dutch researchers warned Kaseya before the attack shifts attention from attribution to the vendor’s vulnerability-response process. It arrives as Biden had already ordered an intelligence investigation into the Kaseya attack, which affected organizations worldwide.
The episode sits early in a broader policy response that later included a [[a:971856|32-country ransomware summit commitment to share attack information and press firms on security]].
First-order effects
Kaseya faces scrutiny over how it received, validated, and acted on the April report of the flaw exploited in the attack.
Biden’s administration gains a concrete vulnerability-management issue to consider alongside the ongoing investigation into the attackers.
Second-order effects
Organizations affected through Kaseya’s software have stronger reason to examine their suppliers’ disclosure and patch-response practices, not only their own defenses.
Security researchers’ reports become more consequential to customers and policymakers when a known flaw is tied to a large-scale incident.
Third-order effects
If governments continue pairing ransomware coordination with pressure on firms to improve security, vendor vulnerability handling will become a more prominent part of ransomware policy rather than a purely internal engineering matter.
The trend: Ransomware response is widening from investigating attackers to improving the cross-border information sharing and vendor security practices that shape attack exposure.
A #malspam campaign is taking advantage of Kaseya VSA #ransomware attack to drop #CobaltStrike. It contains an attachment named “SecurityUpdates.exe” as well as a link pretending to be security update from Microsoft to patch Kaseya vulnerability! https://twitter.com/...
The folks at @DIVDnl did an amazing job with this @kaseya research, even if threat actors ultimately beat Kaseya to releasing the patch. Normally after a vuln like this, more are discovered/exploited. DIVD preempted this activity. #notAllHeroesWearCapes https://csirt.divd.nl/... …
Exclusive? It's been all over the Dutch press for the last day or so and on the DIVD blog before that. Even Kaseya acknowledged it. https://twitter.com/...
The Danish CERT does the community a disservice by not going full-disclosure. I mean, it's their bugs, they can do whatever they want with them, but I'm certain that the benefit to the community of disclosure would outweigh any harm. https://csirt.divd.nl/...
New: Kaseya was notified by Dutch security researchers in early April of a cybersecurity flaw in its VSA software that was used in last week's widespread ransomware attack. The company is still working to push out patches to its customers. https://www.wsj.com/...
The software company connected to a global ransomware rampage that began last week and has damaged hundreds of companies across the world was warned in early April of a cybersecurity weakness utilized in the attack https://www.wsj.com/...