Qualys VMDR Offers Automated Discovery Amid Kaseya REvil Ransomware Attack

The REvil ransomware group exploits a zero-day vulnerability in Kaseya VSA to compromise over a million systems and demand a massive ransom. Qualys VMDR provides tools to automatically identify and prioritize affected assets to help organizations respond.

The REvil ransomware group launches a massive attack by exploiting a zero-day vulnerability, identified as CVE-2021-30116, within Kaseya’s VSA software. This ransomware-as-a-service operation compromises the IT management tool to deploy malicious payloads across the networks of Kaseya customers and their clients. The attackers demand a staggering $70 million for a universal decryptor and claim to lock over one million systems, causing widespread disruptions to supermarkets, schools, and government offices globally.

In response to the crisis, cybersecurity agencies like the FBI and CISA issue urgent advisories and recommend that organizations utilize Kaseya's detection tool to check for indicators of compromise. Kaseya states that the incident primarily affects a small number of on-premises customers. Meanwhile, the REvil group publicly takes credit for the attack on their dark web blog and threatens to leak stolen data on their "Happy Blog" if victims refuse to pay the exorbitant ransom.

To combat this threat, Qualys VMDR provides a streamlined method for organizations to discover and prioritize vulnerable assets automatically. Security teams use specific search queries within the platform to instantly locate systems running the Kaseya Agent. Administrators then apply dynamic tags, such as "REvil ransomware," to continuously group these affected hosts, ensuring that existing and newly discovered systems remain visible and manageable for rapid remediation.

Read More at the original source →