Kaseya VSA Ransomware: 60 MSPs, 1,500 Businesses, One Friday
REvil turned Kaseya’s remote-management platform into a mass-encryption weapon, hitting ~60 MSPs and up to 1,500 downstream businesses days before a patch could land.
REvil turned Kaseya’s remote-management platform into a mass-encryption weapon, hitting ~60 MSPs and up to 1,500 downstream businesses days before a patch could land.
No attack, no breach — a single customer config met a dormant software bug and took Reddit, the Guardian, and roughly a tenth of the internet offline for an hour. The concentration-risk wake-up call.
REvil halted the world’s largest meat processor over a holiday weekend; JBS restored from backups — and still paid $11M for leak suppression and restart insurance. The economics of ransom beyond decryption.
DarkSide entered through a no-MFA legacy VPN password, exfiltrated 100 GB, and encrypted Colonial’s IT — prompting a precautionary shutdown of 45% of East Coast fuel supply. Anatomy of the most policy-consequential ransomware ever.
A tampered Codecov Bash Uploader quietly shipped CI environment variables — cloud keys, tokens, signing material — to attackers for two months. The curl-pipe-bash trust model dissected, and how build supply-chain security was rewritten after.
By March 2021 REvil paired a record $50M Acer demand with leak-site auctions and affiliate economics — industrialised extortion at its zenith. How the machine worked and why every brand since runs its playbook.
A CVSS 9.8 unauthenticated RCE in BIG-IP iControl REST was mass-exploited within a day of disclosure — web shells, credential theft, coinminers on the boxes that hold your TLS keys. The edge-device patch-race case study.
Teenage hackers turned one exposed Verkada dev server into super-admin access over ~150,000 customer cameras — hospitals, jails, Tesla, Cloudflare. The third-party camera risk case that rewrote vendor security questionnaires.
Four zero-days in on-premises Microsoft Exchange let HAFNIUM and ten follow-on crews own mail servers at tens of thousands of organisations. The anatomy of the SSRF-to-web-shell chain, the PATCH NOW scramble, and why patching was not remediation.
HelloKitty ransomware encrypted CDPR’s network and stole Cyberpunk 2077 and Witcher 3 source code — then auctioned it on a crime forum after the studio refused to pay. The incident file on IP extortion, auction economics, and the no-ransom playbook.
No exploits, no stolen credentials — Alex Birsan’s February 2021 research got code executed inside 35+ major companies by registering their internal package names on public registries and letting version arithmetic do the rest. The incident file on the cheapest supply-chain attack ever demonstrated.
A remote intruder raised a Florida treatment plant’s lye setpoint from 100 to 11,100 ppm and an operator watching the screen reverted it in minutes. The incident file on shared passwords, exposed TeamViewer, and why OT security failed at a municipal water utility.