URGENT – KASEYA: This bulletin is for anyone that utilizes a MSP (Managed Service Provider) running KASEYA

**URGENT SECURITY NOTIFICATION**

Executive Summary:

On July 2nd, 2021 Kaseya released an advisory stating that they have been the target of a cyberattack. The attack targets the VSA platform which is a cloud-based IT management and remote monitoring solution with this attack only targeting only On-premise customers. End users are reporting that an automatic update in the VSA appliance dropped the REvil ransomware. Updates will be published as soon as they are available.   PLEASE NOTE: Fusion IT does not utilize this service from Kaseya. 

Recommendations:

  • Shutdown VSA appliances ASAP
    • First method of attack is disabling administrative access to VSA server
  • Block the following latest malicious samples (SHA256) from your environment:
    • d55f983c994caa160ec63a59f6b4250fe67fb3e8c43a388aec60a4a6978e9f1e
    • 8dd620d9aeb35960bb766458c8890ede987c33d239cf730f93fe49d90ae759dd

Read more about this threat here: Kaseya

For additional security bulletins go to https://fusion-it.net/security-bulletin/

Thank you!

Fusion IT, LLC

Interesting Image

Discovery Call Request

 

 

Important! We hate spam as much (or more!) than you and promise to NEVER rent, share, or abuse your e-mail address and contact information in any way.