/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

A Dutch security researcher group says it had notified Kaseya in April about one of the flaws that was exploited in the devastating ransomware attack last week

President Biden is meeting officials to discuss recent attacks, including latest affecting hundreds of organizations around the world

Wall Street Journal

Context & Ripple Effects

The disclosure that Dutch researchers warned Kaseya before the attack shifts attention from attribution to the vendor’s vulnerability-response process. It arrives as Biden had already ordered an intelligence investigation into the Kaseya attack, which affected organizations worldwide.

The episode sits early in a broader policy response that later included a [[a:971856|32-country ransomware summit commitment to share attack information and press firms on security]].

First-order effects

  • Kaseya faces scrutiny over how it received, validated, and acted on the April report of the flaw exploited in the attack.
  • Biden’s administration gains a concrete vulnerability-management issue to consider alongside the ongoing investigation into the attackers.

Second-order effects

  • Organizations affected through Kaseya’s software have stronger reason to examine their suppliers’ disclosure and patch-response practices, not only their own defenses.
  • Security researchers’ reports become more consequential to customers and policymakers when a known flaw is tied to a large-scale incident.

Third-order effects

  • If governments continue pairing ransomware coordination with pressure on firms to improve security, vendor vulnerability handling will become a more prominent part of ransomware policy rather than a purely internal engineering matter.

The trend: Ransomware response is widening from investigating attackers to improving the cross-border information sharing and vendor security practices that shape attack exposure.

Discussion

  • @mbthreatintel Malwarebytes Threat Intelligence on x
    A #malspam campaign is taking advantage of Kaseya VSA #ransomware attack to drop #CobaltStrike. It contains an attachment named “SecurityUpdates.exe” as well as a link pretending to be security update from Microsoft to patch Kaseya vulnerability! https://twitter.com/...
  • @malwarejake Jake Williams on x
    The folks at @DIVDnl did an amazing job with this @kaseya research, even if threat actors ultimately beat Kaseya to releasing the patch. Normally after a vuln like this, more are discovered/exploited. DIVD preempted this activity. #notAllHeroesWearCapes https://csirt.divd.nl/... …
  • @nicoleperlroth Nicole Perlroth on x
    WSJ playing fast and loose with “exclusive” when this is all available on a... website. https://twitter.com/...
  • @gazthejourno Gareth Corfield on x
    Exclusive? It's been all over the Dutch press for the last day or so and on the DIVD blog before that. Even Kaseya acknowledged it. https://twitter.com/...
  • @erratarob @erratarob on x
    The Danish CERT does the community a disservice by not going full-disclosure. I mean, it's their bugs, they can do whatever they want with them, but I'm certain that the benefit to the community of disclosure would outweigh any harm. https://csirt.divd.nl/...
  • @dnvolz Dustin Volz on x
    New: Kaseya was notified by Dutch security researchers in early April of a cybersecurity flaw in its VSA software that was used in last week's widespread ransomware attack. The company is still working to push out patches to its customers. https://www.wsj.com/...
  • @wsj @wsj on x
    The software company connected to a global ransomware rampage that began last week and has damaged hundreds of companies across the world was warned in early April of a cybersecurity weakness utilized in the attack https://www.wsj.com/...