Updates Regarding VSA Security Incident
kaseya.com
kaseya.com
Great job patting yourselves on the back, 9 times... I love how they mention how its sophisticated, localized and quick they were to detect it. Then they drop the details, which are literally the opposite of what they say... it impacted 1500+ businesses, the attackers got in via command injection, they only caught it after customers started complaining.
If you look at the OWASP top 10, they basically ticked 6/10 of the boxes (A1, A2, A3, A5, A8 A10).