Was Kaseya A Supply-Chain Attack, And Why Does It Matter?
If the Kaseya attack was a “supply-chain attack” in terms of the industry accepted definition then it is a stretch of that definition. The distinction is important, because software supply-chain compromises are harder for customers of software solutions to detect using usual defensive measures, and generally involve exploitation techniques that fall outside the scope of web application penetration testing standards. So there is a feeling that essentially no blame rests with the software customer, and perhaps reduced blame rests with the software vendor. In this post we explore the implications for Kaseya of mis-categorising this attack as a supply-chain attack.
