logo

Kaseya VSA Supply-Chain Ransomware Advisory

ID: 4ebcb0b4-f7db-561c-9761-9b211c0bf6ab

STIX ID: report--4ebcb0b4-f7db-561c-9761-9b211c0bf6ab

Feed Name: Zscaler Security Research Blog

Threat Score
90/100

Date Published: 2025-10-10

Date Updated: 2026-05-01

...
...

Zscaler ThreatLabz describes a July 2021 Kaseya VSA supply-chain ransomware incident in which attackers likely exploited a zero-day in the on-prem VSA to distribute a malicious update that dropped a loader and deployed REvil/Sodinokibi, impacting many MSPs and over 1,000 downstream businesses; the advisory details the attack chain, suggested mitigations, and Zscaler detection and sandbox coverage.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.