Search/kaseya
Vendor

kaseya

Known CVEs
0
Highest CVSS
In KEV
0
Vendor
unitrends backup software
Connections
16 relationships
The backup Microsoft never promised you
Confidence in an organization's cyber recovery capabilities deserves scrutiny. If a ransomware attack disables the SaaS data tenanted in the Microsoft cloud ecosystem, the data the business depends on as its lifeblood, the pace at which operations resume rests on assumptions that often prove wrong. Anyone whose answer is "It's all good. Microsoft has my back on this one with its comprehensive native retention and recovery capabilities" is due a reality check. With agile business tools like M365 and Entra ID and solid backend infrastructure in the form of Azure, Microsoft brings a lot to the SaaS party. Both IT departments and MSPs need to be aware, however, that Redmond operates on the same shared responsibility model as other major SaaS providers. In the event of a cyberattack, the recovery burden splits between what the cloud provider handles and what falls to the subscriber alone. MSPs face the additional pressure of meeting stringent SLAs, working with clients’ preferred providers or tooling, and managing their own staffing and profitability accordingly. Microsoft ensures that its services keep running in the aftermath of a strike but does not promise to restore data to a specific known good point before the disaster. That gap always sat with the customer, and planning for it before problems hit beats improvising while picking up the pieces. "There's a common misconception about what Microsoft is responsible for, as distinct from the service they're providing," explains Brent Torre, GM of cyber resilience . Microsoft's native tools, he points out, address problems like short-term accidental deletion and aspects of data governance. They are not a backup solution and will not protect against ransomware or recover data. "Microsoft is clear that whether it's a SaaS application like Microsoft 365, a platform application like SQL Server, or even VMs running in Azure, the customer is always responsible for the information that's in that service, as well as devices, accounts and identities," he adds. "If you get compromised and the attacker starts deleting data, Microsoft has no responsibility for that." A world of pain The gap between availability and true cyber recovery is misunderstood, and it has widened into something of a chasm in recent years. There are three contributing factors to this gap. The first is the evolution of cyberattacks. Typical cyberattacks have pivoted from muscling past a defensive barrier to targeting human weakness, because strolling in through the front entrance with a stolen pass is easier than shimmying through a forced window. Identity has become the primary attack surface. Credential compromise, or identity-based initial access, removes the need to find a vulnerability to exploit and requires only an unwary employee. AI is now a staple weapon in the criminal arsenal, augmenting exploitation techniques such as phishing, social engineering, deceptive emails and spoofed websites, all convincingly used to trick users into typing passwords into a portal controlled by the aggressor. The technique can get more scientific than that. Automated AI-powered bots test millions of leaked username and password pairs across hundreds of different websites, exploiting the common habit of password reuse. Microsoft Entra ID, the vendor's cloud-based identity and access management service and the very tool designed to keep criminals out, is now a prime vector for attack and no match for stolen identity. Once an attacker compromises Entra ID with pilfered credentials, without setting off alarms, they have a free run at gathering data from mailboxes, OneDrive, SharePoint, Teams and other soft targets. The ransomware attack itself can then be launched with ease and at leisure. Another contributory factor is that the vogue for moving workloads to infrastructure and platform as a service (IaaS and PaaS) models shows no sign of abating. Organizations tend to retain some functions on-premises, put some in SaaS applications, and others in cloud environments, but are often guilty of not protecting and managing everything to the same level of quality. Data gets backed up in a variety of locations, yet whether it is all equally recoverable in the event of a breach is another chink in the armor that nobody understands. The 'as a service' model is popular, but it is the weak link when ransomware strikes. The third part of the problem is the emergence of multiple compliance requirements mandating cyber resilience along with correct backup and recovery procedures, for which many organizations are ill-prepared. Together, these pressures give criminals room to do enormous harm to data, business operations and compliance posture in the gap between attack and restoration of SaaS availability. Given that Microsoft's native retention and recovery capabilities are not designed to deliver true cyber resilience, restoring the business to how it was before the attack is something to plan for in advance. Time for independent backup protection "At Kaseya we regularly recommend that you keep a copy of your data, independent of the primary environment it's operating in," advises Torre. "This needs to be something immutable that you can recover from even if the Microsoft or Google or Salesforce ecosystem goes down." This kind of protection is best delivered as a dedicated cloud-to-cloud backup solution stored outside the main SaaS tenant, he argues, an approach increasingly written into cyber insurance and compliance requirements. By pulling copies of regularly targeted data from the Microsoft tenant for storage offsite in a third-party datacenter, organizations can be sure that if SaaS credentials are compromised, critical assets remain safe from attack. Restoration can then push what is needed directly back into the SaaS environment, even where the original tenant has been destroyed. "In fact some people find it faster to stand up a new shell and rebuild it than try to gain access back into a compromised tenant," notes Torre. "Whether you're an internal IT technician, working the night shift, or an MSP needing to live up to your SLAs and maintain profitability, you require a solution that's super straightforward and you need to be able to trust that the recovery will work. Both IT departments and MSPs should be looking out for a solution that's incredibly easy to use. Disaster recovery isn't the only job that they have." A good platform, he says, focuses not just on guaranteeing recovery but on keeping the hygiene of the cyber resilience estate at a high standard without endless human intervention. It should also make certain that Microsoft 365 and Entra ID are restored together in a single workflow, so identity and the data it grants access to come back online in the right order rather than in separate stages. Choosing the right platform Datto is a cybersecurity and data protection business owned by Kaseya. Datto SaaS Protection for Microsoft 365, Datto Backup for Microsoft Azure, and Datto Backup for Microsoft Entra ID are designed between them to close the gap between availability and recovery by storing protected copies of tenant data in the Datto Cloud, outside the Microsoft environment. In this way a compromised production tenant does not take the recovery point down with it. "With our M365 backup, we're protecting one million users worldwide," claims Torre. "A lot of organizations have built trust around our ability to protect and recover their data. We offer a trusted platform for recovery that focuses on ease of recovery, ease of deployment, not just for M365 but for Azure and Entra ID too." Both IT bosses and MSP players need to recognize that a ransomware attack, or other cyber crisis, is a matter of when rather than if. Recovery matters more than protection, because protection is certain to fail at some point, and traditional approaches to backing up data are no longer sufficient on their own. Anticipating disaster is not enough; the organization also needs to be set up to withstand it. That means being as certain as possible that the Microsoft environment can be recovered rapidly, down to the last scrap of data. This capability underpins modern business workflows and operations. Microsoft tracks more than 4,000 identity attacks every second and analyzes 38 million identity risk detections daily — no organization is off the target list. When an attack lands, the restoration clock is already ticking, and any delay in fully restoring IT operations and key environments to their pre-attack state can mean the difference between survival and collapse, with profit, regulatory standing and reputation all riding on the outcome. Securing data with purpose-built cyber resilience platforms that enable rapid, clean recovery is how organizations meet that test. MSPs looking to close the gap can start with the Datto MSP Buyer's Guide to Microsoft Entra ID Backup Sponsored by Datto.
theregister.comAug 13, 2026extracted
The Hidden Security Risks of Reduced Summer IT Coverage
For most organizations, summer means vacation schedules, lighter staffing levels and slower business operations. For cybercriminals, it means opportunity. As IT and security teams operate with reduced staffing levels, attackers actively look for opportunities to exploit slower response times and reduced oversight. They know that suspicious activity is more likely to go unnoticed, giving them valuable time to gain a foothold within an organization's environment. The good news is that security does not have to take a vacation when your team does. With the right mix of automation, monitoring and response capabilities, organizations can maintain strong protection even when key personnel are out of the office. Why cybercriminals love summer For threat actors, summer creates ideal operating conditions. Data indicates a 40% increase in cyberattacks during holiday periods, with the summer months being particularly vulnerable. During vacation season, organizations often face: Smaller security teams covering the same workload: Security alerts, tickets and routine tasks do not decrease during vacation season. With fewer people available, teams must manage the same volume of work with reduced capacity. Senior engineers take planned time off: When experienced team members are away, critical decisions and complex investigations may take longer to resolve, increasing response times during an incident. Institutional knowledge also becomes less accessible: The person who understands why a server behaves unusually or can quickly interpret an obscure alert may not be available. That can slow investigations and make it harder to respond efficiently when issues arise. These staffing gaps create operational bottlenecks across the organization. Patch cycles get delayed, vulnerabilities remain unaddressed for longer and investigations may not receive immediate attention. IT teams struggle to keep up with evolving cyberthreats across client environments. Limited resources and fragmented tools create alert overload and noise hiding threats. Discover how unifying security data into actionable insights reduces fatigue and improves faster accurate detection and response. Download Ebook How summer security gaps can quickly escalate into major incidents The real danger is not just that attacks increase during vacation periods. It is that lean staffing can make common attacks, such as phishing and Business Email Compromise (BEC), harder to spot and easier to act on. The 2026 Kaseya Email Security Report found that as attackers increasingly using AI to make phishing attacks more convincing and scalable, traditional warning signs are becoming less reliable, making fraudulent requests harder to identify and more likely to succeed. With approval chains disrupted and key decision makers out of the office, employees may be less likely to verify urgent requests or question suspicious emails. This creates opportunities for attackers to impersonate executives, vendors, or trusted contacts to steal credentials or divert funds. If these attacks succeed, reduced coverage can delay detection and response, giving attackers more time to operate undetected. In security, this is known as dwell time. The longer attackers remain inside a network, the more opportunities they have to steal credentials, access sensitive data, move laterally or launch a ransomware attack. The real problem: Security still depends too heavily on people Vacation schedules are not the root issue. The bigger problem is that many security operations still rely heavily on human availability. Alert fatigue gets worse Modern environments generate thousands of alerts every day. Most are harmless, but some represent the early stages of a real attack. When teams are fully staffed, analysts have more capacity to investigate suspicious activity and separate genuine threats from background noise. During vacation periods, the same volume of alerts must be reviewed by fewer people, increasing the likelihood of mistakes. Manual processes become bottlenecks Many critical security functions still depend on manual effort. Ticket triage, threat investigations, patch deployment and containment actions all require time and attention. When staffing levels are reduced, these processes slow down. Every delay extends the window attackers have to exploit vulnerabilities, deepen their access or move through systems before anyone intervenes. What appears to be an operational backlog can quickly become a security gap. Security moves at human speed, while attackers do not Attackers increasingly use automation, AI, and prebuilt attack frameworks to scan for vulnerabilities and launch attacks around the clock. They can send thousands of highly targeted phishing emails in minutes or automatically exploit newly disclosed vulnerabilities as soon as they become public. Many organizations, however, still rely on someone reviewing an alert, approving a change or escalating an issue before action can be taken. That creates an imbalance. During periods of reduced staffing, the gap becomes even wider. How AI-driven automation closes the coverage gap If the core challenge is that security depends too heavily on human availability, the solution is not simply hiring more people. It is reducing the number of critical security tasks that require someone to be available at exactly the right moment. AI-driven automation helps organizations maintain consistent security even when staffing levels fluctuate. Automated patching Automated patch management solutions can identify critical updates and deploy them in accordance with predefined policies. Instead of waiting for someone to manually schedule updates, organizations can reduce vulnerability exposure even when key personnel are unavailable. Benefits include: Faster deployment of critical fixes Reduced reliance on individual administrators More consistent patching schedules Intelligent alert prioritization AI-powered security tools can analyze incoming alerts and prioritize those most likely to represent genuine threats. This helps smaller teams focus on what matters most, rather than spending valuable time sorting through noise. Benefits include: Reduced alert fatigue Faster identification of high-risk incidents Better use of limited analyst resources Autonomous runbook execution A security runbook is essentially a set of instructions that defines how to respond to specific incidents. Modern automation platforms can execute portions of these workflows automatically. For example, a system might: Isolate a potentially compromised device Disable suspicious user accounts Trigger remediation workflows Notify the appropriate stakeholders Around-the-clock protection Continuous monitoring helps ensure security coverage remains consistent, even when teams are operating with reduced capacity. This allows organizations to: Monitor systems and user activity 24/7 Detect suspicious behavior in real time Respond to threats outside business hours Maintain visibility during holidays, weekends and staffing shortages Attackers do not take vacations The threat landscape does not pause for summer holidays. If anything, attackers actively look for periods when organizations are operating with reduced coverage. Research from KPMG highlights that vacation periods, including summer breaks and the busy holiday season from October through December, are often prime opportunities for cyberattacks. While employees step away from their desks, threat actors continue probing for vulnerabilities, launching phishing campaigns and searching for signs of slower response times. Security resilience goes beyond summer The organizations best prepared for these seasonal risks are not the ones asking employees to skip vacations. They are the ones building resilient security operations that can maintain visibility, detect threats and respond consistently regardless of staffing levels. That means reducing dependence on manual processes, automating routine security tasks and ensuring critical security functions continue operating even when key personnel are out of the office. As attackers increasingly use AI to scale and accelerate their campaigns, understanding how these threats are evolving has become essential. The 2026 Kaseya Email Security Report explores the latest tactics attackers are using and outlines practical steps organizations can take to strengthen their defenses. Summer may expose the problem, but resilience is valuable year round. Read the report now. Sponsored and written by Kaseya.
bleepingcomputer.comJul 9, 2026extracted
OAuth, guest accounts, and weak MFA drive SaaS risk
OAuth, guest accounts, and weak MFA drive SaaS risk Organizations often create guest accounts to give contractors, suppliers, and partners temporary access to files and SaaS applications. Many of these accounts remain active long after they are needed, creating overlooked access paths to corporate data. Guest accounts accounted for 69% of monitored SaaS accounts in 2025, an increase of more than 1.9 million compared with the previous year, according to Kaseya’s 2026 SaaS Security Report: Closing the Unmanaged Trust Gap. They outnumber licensed users by more than two to one, significantly expanding the attack surface. If left active and unmanaged, these accounts create opportunities for cybercriminals to compromise them through credential stuffing, password spraying, and similar attacks. Guest accounts receive the same permissions as internal employees, including privileged access. AI-assisted account enumeration is making these attacks efficient. Attackers can use automated tools to identify active guest accounts within a tenant, test them for weaknesses, and gain access through dormant accounts. OAuth integrations are expanding the SaaS attack surface Organizations are adopting AI assistants, automation tools, and collaboration platforms that integrate with Microsoft 365 and Google Workspace through OAuth. These integrations allow employees to sign in with existing work accounts and grant third-party applications access to email, cloud storage, calendars, messaging platforms, and other business data. OAuth-connected applications receive broad permissions that remain active after approval. If one of these applications is malicious or becomes compromised, attackers can maintain access through OAuth tokens without stealing passwords. This access can persist even after a user changes their password, making malicious activity difficult to detect. Weak MFA adoption leaves accounts exposed MFA remains one of the most effective defenses against account compromise, with adoption across small and midsize businesses remaining limited. Fifty-six percent of monitored end-user accounts had MFA disabled or inactive, and only 27% of organizations enforced MFA policies across their SaaS environments. Accounts protected only by passwords remain vulnerable to phishing, credential theft, and password reuse attacks. Once attackers gain access, they can operate as legitimate users within SaaS applications, increasing the risk of business email compromise, fraud, and unauthorized access to sensitive data. External file sharing creates persistent data exposure Cloud collaboration platforms make it easier for employees, contractors, partners, and customers to share files across organizational boundaries. The growing use of AI assistants and automated workflows is accelerating this trend as business applications exchange data and employees connect third-party services to corporate SaaS environments. External file sharing increases the likelihood that sensitive business information will remain accessible after collaboration ends. Shared documents may contain financial records, customer data, internal communications, or intellectual property that remain available because of outdated permissions, unmanaged guest accounts, or orphaned sharing links. These links are often created for temporary projects and never revoked, allowing former contractors, partners, or anyone with the original URL to retain access long after the collaboration ends. Trusted infrastructure is undermining login detection Attackers hide behind VPNs, proxy networks, cloud infrastructure, and compromised systems to make malicious activity appear legitimate. This reduces the effectiveness of security controls that rely on IP reputation or geographic location to identify suspicious logins. Remote work, outsourcing, and global collaboration have made unauthorized access harder to detect. Organizations expect legitimate logins from countries associated with remote employees, contractors, cloud providers, and VPN services, making it difficult to distinguish normal business activity from compromised accounts. Growing alert volumes overwhelm security teams SaaS environments generate billions of security events, making it difficult for security teams to distinguish routine business activity from malicious behavior. While most events are low priority, the report recorded nearly 279 million medium- and critical-severity alerts in 2025. Service principal logins became a common source of critical alerts in 2025. Service principals are non-human identities used by applications, scripts, and automation tools to access SaaS services. If compromised, they can provide attackers with persistent access that is difficult to detect than activity originating from standard user accounts. “AI-emboldened threat actors see one interconnected attack environment, whereas most organizations defend their infrastructure in pieces,” said Jim Lippie, chief product officer, Kaseya. “The most resilient organizations will be those that embrace continuous monitoring, identity governance and automated response as foundational requirements.”
helpnetsecurity.comJul 6, 2026extracted
Why AI-driven threats are exposing the limits of MSP security stacks
AI is transforming the speed and scale of cybercrime in ways traditional security operations were never designed to handle. Gartner predicts AI agents will cut the time it takes to exploit account exposures by 50% by 2027. Phishing campaigns that once took days to craft can now be generated in minutes, free of the telltale errors that once gave them away, while vulnerabilities that once required manual reconnaissance can now be identified and exploited automatically. For MSPs, the stakes are clear. Those still relying on a fragmented security stack will not just be slower to respond but will also struggle to prove to clients that their environments are fully protected. Keeping pace with AI-driven threats requires a more unified, AI-powered approach that strengthens security, simplifies operations and delivers greater value without putting additional pressure on margins. The growing gap between attackers and defenders AI is accelerating nearly every stage of the modern attack lifecycle. Verizon’s 2026 Data Breach Investigations Report found that threat actors are already deploying generative AI across multiple stages of the attack chain from reconnaissance and initial access through to malware development. What once demanded significant time and expertise can now be executed faster and at far greater scale. Meanwhile, many MSP technicians are still jumping between disconnected tools to piece together what is happening. An alert fires in the EDR console, but verifying backup status requires a separate login. Patching data lives in the RMM, while remediation steps have to be manually validated across platforms. Every minute spent switching between tools is a minute attackers use to escalate privileges, move laterally and deepen their foothold. The business cost is just as significant. Fragmented operations inflate technician workloads, slow incident response and make it harder to scale cybersecurity services without adding more headcount and tools. All this compounds pressure on margins. In an AI-driven threat environment, security outcomes are increasingly determined by operational speed and coordination, not just the quality of individual tools. AI-driven threats are exposing the limits of fragmented security stacks. Discover how MSPs are simplifying operations, accelerating response and strengthening cyber resilience with an integrated approach. Become a Partner What modern endpoint security operations need Modern endpoint security depends on three capabilities: speed of detection, coordinated response and fast recovery. Achieving all three across multiple disconnected platforms is increasingly difficult. That is why more MSPs are consolidating around unified environments where security, automation, monitoring and recovery operate as a single coordinated workflow. Deep integration Most MSP security tools are connected through lightweight integrations. Data may sync between platforms, but response workflows remain disconnected, making it harder to correlate data quickly and act on threats in real time. Modern endpoint security demands tighter operational integration, where every step of the response process works together automatically. For example, when a ransomware activity is detected, a deeply integrated environment can isolate the device, alert technicians, verify backup integrity, trigger remediation workflows and surface recovery progress from a single interface. This level of coordination reduces time-to-containment, minimizes downtime, and makes compliance reporting significantly simpler. Automation and AI-assisted response Many MSP environments still depend heavily on manual effort during security incidents. That dependence creates dangerous delays when response windows are measured in minutes. Automation closes those gaps by continuously patching vulnerabilities, enforcing security policies, detecting anomalies earlier and triggering remediation without waiting for a technician to act. This matters not just for speed, but for scale. As attack volumes grow and response windows shrink, automation prevents security teams from being overwhelmed during active incidents and allows MSPs to deliver consistent protection across a larger client base without proportional increases in staffing. Reducing tool sprawl Automation and speed are difficult to sustain when security operations are weighed down by too many disconnected products. Over time, many MSPs have layered on new tools to address emerging threats, client requirements or compliance obligations. The result is overlapping functionality, fragmented workflows, and mounting operational overhead that erodes both efficiency and profitability. Cutting unnecessary complexity allows teams to move faster, respond more consistently, lower licensing costs and deliver a clearer, more confident security story to clients. Security as a growth engine for MSPs As the MSP market matures, security has emerged as one of the clearest drivers of consistent revenue growth and client retention. The 2026 Kaseya State of the MSP research shows 71% of MSPs reported year-over-year cybersecurity revenue growth, the highest of any service category, while 61% say most or all of their clients rely on them for cybersecurity guidance. But the biggest barrier to expanding security services is not demand. It is the combination of tool complexity and talent constraints. Hiring experienced security professionals is expensive and layering in new products to keep pace with evolving threats increases operational overhead while making environments harder to manage. MSPs need security operations that scale without requiring proportional increases in labor, complexity or cost. That is where unified security platforms with truly integrated AI and automation capabilities become operational multipliers. Faster remediation, cleaner visibility and stronger reporting allow MSPs to demonstrate security value more effectively, building the kind of trust that deepens client relationships and creates durable revenue. Why unified platforms are gaining traction Many MSPs are reaching the limits of what fragmented security stacks can efficiently support. Managing separate products for endpoint protection, backup, RMM, patching, MDR and ransomware recovery creates operational silos that slow response and increase administrative burden. Modern all-in-one platforms address this by bringing security, management, and recovery workflows under a single operational model. Kaseya 365 Endpoint reflects this approach. It combines RMM, endpoint security, patch management, backup, ransomware protection, MDR or 24/7 SOC services in one platform. The value is not just fewer tools, but that prevention, detection, response and recovery can operate as a coordinated whole, reducing visibility gaps and enabling faster response with less overhead. As tool complexity and cybersecurity talent shortages continue to limit security growth, Kaseya 365 Endpoint directly addresses both by simplifying operations and helping teams manage security more efficiently without adding specialized staff. Endpoint security in the age of AI AI is changing endpoint security on both sides of the fight. Attackers are using AI to launch faster, more sophisticated threats, while MSPs are under growing pressure to respond and recover more quickly. As attack timelines shrink, clients are judging MSPs not only on their ability to detect threats, but on how quickly they can respond, recover systems and communicate clearly during an incident. Integrated security platforms support this by bringing visibility, response and recovery into a more connected operational model. Faster remediation, clearer reporting and reduced operational overhead will help MSPs demonstrate security value more effectively, strengthening client trust and supporting long term recurring revenue growth. AI-driven threats demand smarter security. Join the Kaseya partner community. Sponsored and written by Kaseya.
bleepingcomputer.comJun 11, 2026extracted
How SIEM helps MSPs reduce noise and stop threats faster
MSPs are flooded with security alerts every day, yet many still struggle to separate operational noise from the threats that actually put customers at risk. One of the biggest reasons is tool fragmentation. When security tools operate in silos, they often create duplicate alerts, blind spots and incomplete context. Instead of gaining improved visibility, MSPs are left piecing together information across multiple consoles just to understand what’s happening in a client’s environment. The impact goes beyond security. For MSPs trying to grow, retain clients and compete against larger providers, alert fatigue and operational inefficiency are becoming business problems too. That is why the conversation around unified security platforms such as SIEM has become increasingly crucial. Fragmented security stacks create security gaps Most MSP security stacks evolved gradually over time. One tool was added for endpoint visibility, another for cloud monitoring and another for email security or network traffic analysis. Individually, these tools may generate useful detections, but they rarely work together in a meaningful way. For example, a suspicious login may appear in an identity tool, unusual PowerShell activity may trigger an endpoint alert and outbound traffic spikes may show up in a network monitoring platform. Viewed separately, each event may seem low priority. But together, they could indicate an attacker has compromised credentials, established persistence and started moving laterally across the environment. Research reports show that 87% of intrusions now involve activity across multiple attack surfaces. At the same time, IBM’s 2025 Cost of a Data Breach Report found that organizations take an average of 241 days to identify and contain a breach. MSPs are not losing visibility because they lack tools. They are losing visibility because the tools are not working together. Why SIEM has become essential for MSPs Modern attacks rarely remain confined to a single area of the environment. Threat actors move between systems, user accounts, cloud applications and connected infrastructure as part of the same attack. A modern SIEM changes that by giving MSPs a centralized view of activity across the entire environment while automatically correlating related events into a single investigation workflow. Instead of technicians manually pivoting between consoles and chasing disconnected alerts, the platform connects signals into a cohesive attack narrative with the context teams need to act quickly. For lean MSP teams, that becomes a force multiplier. Investigations move faster because technicians no longer waste hours reconstructing timelines across disconnected platforms. Threats are easier to identify because suspicious behavior can be tracked across multiple attack surfaces rather than being hidden in isolated alerts. Teams spend less time chasing noise and more time responding to incidents that could impact clients. Automated correlation and response reduce manual workloads, helping MSPs improve efficiency without constantly adding headcount. That visibility is critical for reducing alert fatigue. Rather than overwhelming teams with isolated notifications and duplicate investigations, SIEM helps filter noise, prioritize meaningful incidents and surface the threats that require attention. IT teams struggle to keep up with evolving cyberthreats across client environments. Limited resources and fragmented tools create alert overload and noise hiding threats. Discover how unifying security data into actionable insights reduces fatigue and improves faster accurate detection and response. Download Ebook The business case for SIEM is growing stronger Kaseya’s 2026 State of the MSP Report found that winning new clients is becoming harder, competition is increasing and differentiation is difficult when most MSPs offer similar service stacks. Security, however, remains one of the few areas where MSPs have a growth opportunity. Clients are paying closer attention to security maturity, response capabilities, compliance readiness and operational resilience. That creates a major opportunity for MSPs that can position security as more than just another toolset. SIEM sits at the center of that conversation because it helps MSPs improve both security outcomes and operational efficiency at the same time. The key is learning how to position that value correctly. Make the invisible visible. Most clients assume they are protected because they have antivirus and a firewall. Show them — with a demo or a report — how many signals their environment generates across endpoints, cloud and identity that go uninvestigated without unified visibility. The gap becomes real the moment they can see it. Sell confidence, not coverage. The question your clients are really asking is, “If something happens, will you catch it?" Your pitch should answer that question directly. Unified detection, automated response and 24/7 SOC support mean the answer is yes, and you can prove it. Bundle it as a business continuity conversation. Cyber insurance providers, regulators and enterprise procurement teams increasingly require demonstrable security posture. Positioning SIEM not just as protection but as a compliance and insurability enabler makes it a business necessity rather than a cost. MSPs that can connect security operations to measurable business outcomes will become far harder to replace and far less likely to compete on price alone. Closing the detection gap with Kaseya SIEM MSPs are often forced to choose between two difficult options. Traditional enterprise SIEM platforms can be expensive, complex to manage and difficult for lean teams to fully operationalize. On the other hand, lightweight managed alternatives may simplify operations but often come with visibility, customization and response limitations. The result is a frustrating tradeoff. Overpay for complexity that many teams cannot effectively use or settle for tools that cannot deliver full visibility into modern threats. MSPs need a middle ground that provides enterprise-grade detection and response capabilities without adding overwhelming operational overhead. Kaseya SIEM is designed to fill that gap. Unified visibility: With visibility across more than 60 data sources, Kaseya SIEM unifies endpoint, network and cloud telemetry into a single dashboard with automated response capabilities and 24/7 SOC support built in. Fast automated response: Kaseya SIEM helps MSPs react in minutes instead of hours with automated response actions that work across cloud and endpoint environments simultaneously. Teams can isolate devices, block accounts, flag suspicious sessions and trigger response workflows automatically. Smarter investigations with AI: Kaseya SIEM uses AI to simplify investigations and reduce alert fatigue for MSP teams. Its AI-powered interrogation chatbot allows technicians to query security data using natural language, while behavior-based detections help uncover suspicious activity that traditional rules-based systems may miss. Proactive security recommendations: The platform can also recommend alert suppressions for known-good behavior, surface indicators of compromise, suggest PowerFilters to reduce noise and provide Microsoft tenant hardening recommendations to proactively strengthen security posture. Turning signals into answers The signals are already there. In most breach postmortems, the indicators existed in the logs long before the incident escalated. The problem was that no one connected them fast enough to act. The MSPs that will stand out are those that can reduce noise, improve visibility and turn disconnected alerts into actionable insights. Our eBook, Finding signal in the noise, shows how. Sponsored and written by Kaseya.
bleepingcomputer.comMay 28, 2026extracted
Webinar: Why MSPs must rethink security and backup strategies
Cyberattacks are evolving faster than most managed service providers (MSPs) can keep up with, with phishing now acting as the primary entry point for many compromises. As attackers increasingly use AI to generate highly personalized phishing campaigns, traditional defenses are struggling to detect and block these threats before access is gained. However, the bigger challenge often comes after the initial breach, when organizations are left dealing with data loss, downtime, and recovery. On Thursday, May 14, 2026, at 2:00 PM Eastern Daylight Time, experts from BleepingComputer and Kaseya will host a live webinar exploring how modern attacks unfold and why MSPs must rethink both security and recovery strategies. Security alone isn’t enough without recovery While preventing attacks remains critical, the reality is that not every threat can be stopped in time. Many MSPs still treat security and backup as separate functions, creating gaps that attackers can exploit after initial access. This session will examine how attacks progress from AI-driven phishing and business email compromise to ransomware and data-loss events, and how threat actors increasingly leverage trusted infrastructure and SaaS platforms to bypass defenses. The webinar will also highlight why SaaS backups and a business continuity and disaster recovery (BCDR) strategy are essential components of cyber resilience, ensuring organizations can recover quickly and minimize impact when incidents occur. During the session, attendees will learn: Why AI-driven phishing and brand impersonation are outpacing traditional email security How attackers leverage trusted infrastructure and SaaS platforms to bypass defenses Where most MSP security strategies fail after initial compromise Why SaaS backups and a BCDR plan are critical layers of cyber resilience How leading MSPs combine prevention, detection, and rapid recovery to protect clients and maintain uptime Join this webinar to learn how to strengthen both your security posture and recovery capabilities, helping ensure that even if an attack succeeds, the outcome remains under your control.
bleepingcomputer.comMay 4, 2026extracted
Kaseya agentic IT management unifies data and automates ticketing, security and backups
Kaseya agentic IT management unifies data and automates ticketing, security and backups Kaseya has introduced an agentic IT management platform powered by Kaseya Intelligence, combining unified data across IT operations, cybersecurity, and resilience with an execution layer that autonomously triages tickets, contains threats, verifies backups, and optimizes workflows. This is the core architectural difference. Every major vendor has added AI, but when it runs on partial data and disconnected tools, it often produces inaccurate recommendations that create more work, not less. Kaseya unifies data across endpoints, help desks, security operations, and backup infrastructure, paired with the ability to execute across all systems from a single platform. The result is not just intelligence, but accurate, autonomous action. “The industry doesn’t need another AI feature bolted onto a disconnected tool,” said Rania Succar, CEO of Kaseya. “What MSPs and IT teams need is a platform that runs their operations – one that sees across every system, understands context, and acts autonomously. That’s what we’ve built. Kaseya Intelligence is the engine. The platform is the operating system. And the outcome is IT that manages itself.” Kaseya Intelligence is the engine at the core of the platform, built on more than 1 billion help desk tickets, 3 exabytes of backup data, and 17 million managed endpoints. This is not a general-purpose AI layer. It is a purpose-built system trained on real-world data. Data alone is not enough. What matters is what happens after the AI makes a decision. Kaseya’s platform closes the loop by executing actions, validating outcomes, and learning from them. This is the difference between AI as a feature and AI as an operating system. The platform vision is already being delivered across three major releases announced today at Kaseya Connect Global: Agentic Digital Specialists The service delivery layer powered by Intelligence. Kaseya has introduced AI-powered Digital Specialists that autonomously handle high-volume IT tasks, starting with Ticket Triage, which automatically categorizes and routes tickets with high accuracy, reducing errors and accelerating resolution. “20 to 30% of our tickets aren’t categorized correctly today,” said Koos Ligtenberg, Business Unit Director, Advisor ICT. “That creates all kinds of downstream issues – including billing inaccuracies. From what we’re seeing in early testing, we believe the Ticket Triage Digital Specialist will eliminate up to 80% of those errors. This is a huge deal for us.” Unified Cyber Resilience Kaseya has unified on-prem, SaaS, Endpoint, and Cloud backup into a single integrated portal, eliminating the fragmented tool sprawl that forces technicians to manage recovery across disconnected vendors. Powered by Kaseya Intelligence, the Unified Cyber Resilience Portal delivers actionable insights through connected workflows and intelligent prioritization, AI-driven screenshot verification with greater than 99.9% accuracy, and compliance coverage including FIPS capabilities and FedRAMP readiness. Coverage is expanding further across cloud and virtualization. Azure Files support is now generally available, extending Azure VM protection to file shares and unstructured data, giving partners a cost-effective way to protect critical Azure workloads beyond a single-cloud environment. Agentless Hyper-V backup follows in June 2026, protecting virtual machines without individual agents to deploy or maintain. Kaseya SIEM Kaseya SIEM is now generally available, a purpose-built solution that delivers enterprise-grade security operations for MSPs and IT teams without the complexity and cost of traditional SIEM platforms. It unifies telemetry across endpoint, network, cloud, identity, and email, correlating signals from more than 60 data sources to detect and respond to threats across the full attack surface. Unlike SIEMs that require dedicated security engineers, or managed-only offerings that limit control, Kaseya SIEM gives IT teams enterprise-grade detection without enterprise-grade staffing. Cross-surface correlation shows technicians the attack picture in one interface, without a specialist to parse it. Automated response contains threats in minutes, acting across systems instead of bouncing alerts back to a human. Tunable detection cuts noise, and 400-day log retention covers compliance out of the box. For customers who’d rather not run a SOC in-house, a 24/7 team of real security experts, accelerated by Kaseya Intelligence, delivers the coverage of a dedicated SOC without the burden of building one.
helpnetsecurity.comApr 29, 2026extracted
Google links axios supply chain attack to North Korean group
Google links axios supply chain attack to North Korean group Hackers connected to North Korea are responsible for the recent compromise of a wildly popular library used in both front-end apps and back-end systems, according to new researcher. On Monday evening, news emerged that hackers launched a supply chain attack targeting the HTTP client axios, which is downloaded 100 million times each week and embedded across frontend frameworks, backend services and enterprise applications. Google Threat Intelligence Group (GTIG) joined several other researchers in attributing the attack to a North Korean threat actor they call UNC1069. SentinelOne found the same group using macOS-based malware in attacks dating back to 2023. Last month, the financially-motivated group was accused of targeting a cryptocurrency company with several unique pieces of malware deployed alongside multiple scams, including a fake Zoom meeting. Several other researchers backed Google’s assessment because the backdoors used during the axios attack resemble WAVESHAPER, a strain of malware North Korean actors used during the fake Zoom campaign. John Hultquist, chief analyst at Google Threat Intelligence Group, said the axios incident is unrelated to another recent supply chain attack that caused alarm among security experts due to its widespread nature. Hultquist noted that North Korean hackers “have deep experience with supply chain attacks, which they’ve historically used to steal cryptocurrency.” A 2023 supply-chain attack on the enterprise phone company 3CX was attributed to North Korean hackers. “The full breadth of this incident is still unclear, but given the popularity of the compromised package, we expect it will have far reaching impacts,” Hultquist said. Experts raised alarms early on Tuesday morning when two malicious versions of the axios package were published on the Node Package Manager (npm). Security companies Socket and StepSecurity confirmed the packages were malicious and traced the incident back to the hijacking of the lead axios maintainer’s npm account. Socket said the malicious package deploys a multi-stage payload, including a “remote access trojan (RAT) capable of executing arbitrary commands, exfiltrating system data, and persisting on infected machines.” “When the attack first happened, axios maintainers were unable to regain control of the project. In a public GitHub issue, a collaborator stated they could not revoke access from the account responsible for the malicious publish, noting that the attacker’s permissions exceed their own,” Socket explained. Axios is among the most popular JavaScript HTTP client libraries and is used by developers to connect apps to the internet. StepSecurity said that this is “among the most operationally sophisticated supply chain attacks ever documented against a top-10 npm package.” The malicious version injects a new dependency that installs the malware, which impacts Windows, macOS and Linux. After executing, the malware deletes itself and replaces it with a clean version of the tool to evade detection, StepSecurity added. “There are zero lines of malicious code inside axios itself, and that's exactly what makes this attack so dangerous,” the researchers said. The incident marks the latest in a string of compromises involving the software supply chain, which is increasingly tied together through code pulled in from outside sources. Last week’s attack on the widely used open-source Python package LiteLLM allowed cybercriminals to breach several organizations. Previous incidents involving XZ Utils and self-replicating worm Shai-Hulud stood out among a sea of research uncovering more and more npm packages that have been corrupted. Mandiant CTO Charles Carmakal said the number of recent software supply chain attacks is overwhelming. “The secrets stolen over the past two weeks will enable more software supply chain attacks, software-as-a-service environment compromises (leading to downstream customer compromises), ransomware and extortion events, and crypto heists over the next several days, weeks, and months,” he said. “We are aware of hundreds of thousands of stolen credentials. A variety of actors with varied motivations are behind these attacks. The blast radius of yesterday's axios npm supply chain attack is broad and extends to other popular packages that have dependencies on it.” Mike Puglia, a security leader at Kaseya, said the incidents are further evidence of the fragility of the world's software ecosystem. “In this case, the attacker compromised one single account, the maintainer of axios, and the malicious code was ‘live’ for almost three hours before discovery. On a typical day, that could mean tens of thousands of organizations received the malware,” Puglia said. To further complicate matters, after the attacker's remote access was deployed, the malware replaced itself with the legitimate axios files, making it difficult to know if you were compromised, he added. Several other experts warned that the recent attacks on axios and LiteLLM would be templates for other hackers to replicate. Jonathan Greig is a Breaking News Reporter at Recorded Future News. Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.
therecord.mediaMar 31, 2026extracted
BarracudaONE adds AI-powered tools to help MSPs simplify security
BarracudaONE adds AI-powered tools to help MSPs simplify security Barracuda Networks unveiled enhancements to its AI-powered BarracudaONE platform. New capabilities, including bulk remediation for email threats, PSA integrations for automated billing and invoicing, and streamlined account management, are purpose-built for managed service providers (MSPs), helping them accelerate security across multi-tenant environments, simplify operations, and drive scalable growth. “These new capabilities underscore Barracuda’s unwavering commitment to helping MSPs scale securely, respond to threats faster and operate with greater agility,” said Michelle Hodges, SVP of global channels and alliances at Barracuda. “Aligned with our partner-first mission, we’re equipping MSPs with the tools they need to grow their businesses and deliver exceptional protection to their customers. By embedding automation and intelligence into daily workflows, we’re enabling our partners to achieve stronger, more profitable outcomes — with greater speed, precision and impact.” Purpose-built enhancements for MSPs New enhancements are designed to help MSPs respond faster, operate smarter and scale with confidence. Advancements include: Bulk remediation for email threats: Barracuda Email Protection now enables MSPs to remediate email threats across all customer environments with a single click, accelerating response times by up to 10x. This rapid containment reduces threat exposure and minimizes escalations. By streamlining threat management and ensuring consistent protection across tenants, MSPs can enhance service delivery, reduce overhead and strengthen trust with customers. PSA integrations for automated billing and invoicing: BarracudaONE now seamlessly integrates with six leading professional services automation (PSA) platforms , including Autotask by Datto, ConnectWise PSA, HaloPSA, Kaseya BMS, Pulseway PSA, and Syncro, enabling MSPs to automate billing and invoicing across multiple customer environments. These integrations validate the openness of the BarracudaOne platform and eliminate manual data entry, reduce errors and accelerate revenue cycles. MSPs can retain their existing workflows while unlocking new efficiencies, improving billing accuracy and minimizing disputes. BarracudaONE unifies security to strengthen threat protection and resilience BarracudaONE maximizes threat protection and cyber resilience by unifying layered security defenses and delivering deep, intelligent threat detection and response. The platform brings together Barracuda’s comprehensive portfolio into a single, integrated experience, simplifying security operations and improving visibility across environments. With embedded automation, natural language queries and intelligent reporting, MSPs can manage solutions, accounts, licenses, and threat response across their customer base from one centralized dashboard, now further enhanced through integration with the Barracuda MSP application. This embedded experience simplifies account management, reduces context switching and boosts overall productivity. These latest enhancements empower MSPs to streamline service delivery, automate invoicing and strengthen customer trust, making BarracudaONE a foundation for scalable growth and resilient cybersecurity.
helpnetsecurity.comOct 15, 2025extracted
Hacker Alleges Russian Government Role in Kaseya Cyber-Attack
A hacker involved in the supply chain attack that targeted IT service provider Kaseya in July 2021 has claimed that he was coerced by the Russian government. Yaroslav Vasinskyi, a former affiliate of the REvil ransomware syndicate known as ‘Rabotnik,’ serves a sentence of over 13 years in US federal prison at the Federal Correctional Institution, Danbury (FCI Danbury), Connecticut. In a six-month conversation with Jon DiMaggio, chief security strategist at Analyst1 and author of the ‘Ransomware Diaries’ series, where he investigates the ransomware ecosystem, Vasinskyi revealed he tried to leave REvil several times for “moral” reasons but was blackmailed into preparing the Kaseya attack before leaving. Vasinskyi claimed REvil has ties with the Russian government and that the people who blackmailed him to keep conducting cyber-attacks were likely from Kremlin-linked government institutions. DiMaggio unveiled his findings during a talk he gave alongside Trellix’s head of threat intelligence, John Fokker, at the DEFCON 33 event in Las Vegas on August 9. The full written version of his investigation was published in the Ransomware Diaries Volume 7 report on August 9. REvil Recruitment, Moral Crisis and Attempted Exit Vasinskyi started working for REvil in early 2019 when he was “recruited” by a member of the group known as ‘Lalartu’ after finding a vulnerability in a ConnectWise server that was linked to around 1000 compromised PCs with various command-and-control (C2) functions. He operated out of Poland, with a few trips to Ukraine while working with REvil. During his email and phone conversations with DiMaggio, Vasinskyi claimed he attempted to leave REvil in March 2020 out of the belief that the deaths of this girlfriend's father and his grandmother were sanctioned against him for conducting cybercrime activities. Additionally, Vasinskyi told DiMaggio that he “grew uneasy” and felt moral regrets after alleged REvil cyber-attacks against a Baptist church and a hospital, the latter reportedly led to a patient dying. After asking REvil’s kingpin, an individual using the moniker UNKN, about this alleged death, Vasinskyi was told that although it was not an intended consequence, it ended up with “good publicity” for the ransomware gang. While further investigation by DiMaggio seemed to indicate that the deadly cyber-attack against a hospital was likely conducted by Ryuk instead of REvil, “the casual dismissal of human death as good advertising’ disgusted Vasinskyi,” the security researcher wrote. “It confirmed what he already feared, that the operation he had once rationalized as transactional had evolved into something colder, more detached, and more dangerous. Grieving, exhausted, and angry, Vasinskyi stepped away from REvil.” Surveillance and Blackmail However, Vasinskyi said his entire life was then under surveillance by some high-level institution. When he travelled to Kyiv’s Boryspil airport in January 2021, he was stopped at passport control by customs, searched and driven out of the airport. According to Vasinskyi, he was under pressure from someone connected to Ukrainian law enforcement who held leverage over him. He later disclosed that one of these contacts was a powerful, high-ranking former intelligence officer. The blackmail, Vasinskyi claimed, was politically motivated, not financial. The handler’s influence stretched far beyond Ukraine, hinting at either deep international intelligence ties or a sprawling cross-border corruption network. “Vasinskyi’s worst fear had been confirmed. His ‘old friends’ leveraged their reach and power to create his legal troubles in Kyiv, and now they were using them to control him,” DiMaggio wrote. What they wanted, Vasinskyi said, was for him to continue working with REvil. If he refused, they allegedly threatened to make sure he would go to jail, be tortured and even do harm to his girlfriend and family members. Back in Poland, where Vasinskyi was based, the surveillance continued and his “handlers,” as he called the people pressuring him, were everywhere he went. Kaseya, A Strategic Target According to Vasinskyi, his “handlers” chose Kaseya as his next target “specifically for the cascading access its software provided, seeing an opportunity to inflict maximum damage through the company’s software distribution capabilities to thousands of downstream clients,” DiMaggio wrote. Vasinskyi admitted to DiMaggio that he had entirely prepared the attack himself, from initial access to testing the final payload. However, he did not want to launch it himself and handed the payload delivery phase over to REvil. He also tried several ways to show that he did not execute the attack himself, including: Sending a letter to the FBI before the attack Using speakerphone during conversations with the REvil leadership team so that investigators potentially surveilling him could hear the conversations Showing his face to CCTV cameras while leaving Poland for Ukraine on the day the attack was executed However, none of these pieces of evidence were used in Vasinskyi’s defence and he ultimately submitted a guilty plea. UNKN, the persona behind which someone was running REvil, disappeared after the Kaseya attack, which compromised over 1500 companies across 17 countries and forced schools, pharmacies and entire supermarket chains offline. Kaseya: Three-Tiered Operation with State-Level Handlers While the Kaseya attack was attributed to REvil and a $70m ransom was demanded, Vasinskyi’s account suggests that the ransomware gang’s true role was strictly as a technical contractor, not an operational commander. According to Vasinskyi in DiMaggio’s reporting, REvil was only responsible for the build as an .exe file, nothing more, nothing less. “They provided the weapon, but his handlers gave the order and pulled the trigger. This testimony lays out a three-tiered operational structure, separating REvil’s role as the ransomware provider from Vasinskyi’s as the technical lead tasked with preparing the attack and a third party, his state-level handlers, as the execution team,” DiMaggio explained. “This wasn’t supposed to be about extortion. It was about disruption: crippling downstream systems, collecting intelligence, and gaining access to critical infrastructure,” the researcher added. Additionally, Vasinskyi claimed that while REvil had connections to Russian government authorities, his own handlers were more powerful – operating at a level even the ransomware group couldn’t reach. This suggested that his troubles stemmed not just from cybercriminal ties, but from entanglement with high-ranking figures whose influence eclipsed even that of REvil’s government-linked associates. A theory on Russian cybercrime forums suggested that UNKN might have been Aleksandr Ermakov, a former Russian police officer arrested in July 2021 shortly after UNKN vanished. However, Vasinskyi disputed this, confirming Ermakov was part of REvil but not the only one associated to UNKN. He believes that two people controlled the UNKN account: Ermakov, who took orders, and one who gave them. The true leader, Vasinskyi insisted, remained "Unknown." During his DEFCON talk, Analyst1’s DiMaggio highlighted that, while cybercriminals tend to lie a lot, Vasinskiy seemed to have never lied about things the researcher tested him on. “At this point, he didn't have much to lose. There wasn't really a reason for him to lie to me. He's been sentenced to 13 years and seven months in prison, he's got $16m in restitution to pay and he has no chance of parole," conclude DiMaggio. Photo credits: Felix Mizioznikov / mundissima / Shutterstock.com
infosecurity-magazine.comAug 12, 2025extracted