logo

Stop the Next Kaseya Attack

ID: d2198123-3951-54d0-a95e-994b6ee831a3

STIX ID: report--d2198123-3951-54d0-a95e-994b6ee831a3

Feed Name: Zscaler Security Research Blog

Threat Score
90/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

While many Americans were on holiday, attackers exploited a zero-day in the on-premises Kaseya VSA management server to distribute REvil ransomware in a supply-chain campaign that affected 40–60 MSPs and more than 1,000 of their customers; the report outlines REvil’s common entry methods (phishing, RDP compromise, WebLogic exploits), the prevalence of double extortion (data theft plus encryption), and prescribes Zero Trust controls—full traffic inspection, microsegmentation, least-privilege access, DLP, CASB, and active deception—to prevent compromise, lateral movement, and data exfiltration.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.