Software company Kaseya has confirmed that approximately 1,500 businesses were affected by an exploit in the company's remote device management software, which was used to spread the REvil ransomware.

The attackers carried out a supply chain ransomware attack, exploiting a vulnerability in Kaseya's VSA software, which is used by many MSPs. This affected both themselves and their customers.
“To date, we are aware of fewer than 60 Kaseya customers using the VSA product who were directly compromised by this attack. As many of these customers provide IT services to many other companies, we estimate that a total of approximately 1,500 companies may have been impacted. We have not found evidence that any of our SaaS customers have been compromised,” Kaseya said.
See also: The group behind Trickbot is linked to the Diavol ransomware
The attackers exploited a vulnerability in Kaseya's VSA software, a remote monitoring and management software used to manage endpoints such as computers, servers and cash registers. It is also used to manage and fix vulnerabilities. The company had been notified of the vulnerability by researchers and had created a patch, but had not yet released it to its customers.
On Sunday, the REvil ransomware gang demanded $70 million for the provision of a decryption tool, which would unlock the systems of all victims.
Learn more: REvil ransomware Kaseya: Hackers demand $70 million to decrypt all systems

Kaseya said that no other of the company's products have been compromised.
However, although VSA's software-as-a-service (SaaS) line was not affected, the servers were taken offline.
A patch for customers running VSA should be available 24 hours after the company's SaaS servers are restored, which it estimates will happen today, July 6, Kaseya said in an update.
See also: Kaseya Ransomware Attack: Biden Calls on Affected Companies to Report It
The company worked with the FBI and CISA to investigate some key elements before restoring the systems.
Kaseya has also released a new free detection toolthat customers can use to monitor their networks and computers. Kaseya's tool looks for indicators of compromise, data encryption, and the REVil ransomware gang's ransom note.
Kaseya urges customers to keep VSA servers offline until it is safe to proceed with recovery efforts.
Source: ZDNet
