HomeSecurityKaseya: Former employees had informed about vulnerabilities years ago

Kaseya: Former employees reported vulnerabilities years ago

Former Kaseya told Bloomberg that they had been informing senior executives about vulnerabilities in its software for years, but were ignored. Several employees resigned or were fired after repeated reports of the company’s poor security practices. In recent days, Kaseya has been in the spotlight due to a massive ransomware attackthat exploited a vulnerability in the company’s software and affected more than 1,000 companies worldwide.

See also: Kaseya: Warns of phishing campaign promoting fake security updates

Kaseya employees

Between 2017 and 2020, employees reported “cybersecurity concerns” to their managers, alleging that Kaseya used outdated code, implemented poor encryption, and failed to regularly update its software and servers. This information was leaked by five former Kaseya employees who spoke to Bloomberg on condition of anonymity.

Two former Kaseya employees said they alerted executives to vulnerabilities in the old Virtual System Administrator software, the system that hackers exploited to launch this latest attack. Kaseya's customers, mostly MSPs, provide remote IT services to hundreds of smaller businesses and use VSA servers to manage and push software updates to those customers.

See also: Ransomware businesses: Negotiators are in high demand

According to initial reports, hackers gained access to Kaseya’s backend infrastructure to send malware, disguised as a software update, to VSA servers. They used the malicious update to install ransomware on every workstation connected to VSA systems. The Russian ransomware gang REvil has claimed responsibility for the attack and has even demanded $70 million for a universal decryption tool.

Kaseya vulnerabilities

A former employee told Bloomberg that in 2019 he sent Kaseya a 40-page report detailing his security concerns. According to the employee, it was one of several attempts he made to inform the company about the risks during his tenure. He was fired two weeks later and believes that this was because of his efforts.

See also: Ransomware: Could a ban on paying ransoms reduce attacks?

Another former employee alleged that Kaseya had stored unencrypted customer passwords on third-party platforms and rarely made updates to its software or servers.

Vulnerabilities in Kaseya's software have been used in ransomware attacks in 2018 and 2019, according to employees. Unfortunately, this was not enough to convince the company to rethink its cybersecurity standards.

Kaseya commented on the claims of former employees (in Gizmodo):

“Kaseya's focus is on customers who have been affected, not on random speculation by former employees or the broader public“.

However, hackers have exploited similar vulnerabilities to launch large attacks in the past, so it's not hard to believe the employees' claims.

Source: Gizmodo

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS