Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

News

12/18/2020
10:40 AM
Jai Vijayan
Jai Vijayan
Slideshows
Connect Directly
Twitter
LinkedIn
RSS
E-Mail

5 Key Takeaways From the SolarWinds Breach

New details continue to emerge each day, and there may be many more lessons to learn from what could be among the largest cyberattacks ever.
2 of 6

Remote Monitoring and Management Tools Are an Attack Vector
The SolarWinds incident shows how remote monitoring and management (RMM) tools present an attractive attack vector, says Eran Farajun, executive vice president at Asgira. Many managed service providers use RMM tools to monitor client networks, endpoints, and devices. SolarWinds has thousands of MSPs as its customers; together, they have hundreds of thousands of clients among them.
RMM tools require an agent to be installed on client servers, hypervisors, workstations, networking devices, laptops, and other mobile endpoints, which give them deep access into enterprise networks. 'RMM agents/probes normally have OS and below level access,' Farajun says. A variety of agents monitor things such as patch and version levels, and hardware performance issues including CPU, memory, fan speeds, and other functions. 'These agents/probes are normally not well protected, if at all,' Farajun says.
When MSPs use their RMM platform with tightly integrated backup solutions, it provides a single access point for attackers to target dozens, hundreds, or even thousands of organizations, he notes. 'One of the best practices is to ensure your most important tools are 'app-gapped,' which means they are not integrated into a common platform, which, if compromised, enables the attackers to use it as a proxy to traverse any other tightly integrated application within a platform,' he says.
Image credit: Mr.B-king via Shutterstock

Remote Monitoring and Management Tools Are an Attack Vector

The SolarWinds incident shows how remote monitoring and management (RMM) tools present an attractive attack vector, says Eran Farajun, executive vice president at Asgira. Many managed service providers use RMM tools to monitor client networks, endpoints, and devices. SolarWinds has thousands of MSPs as its customers; together, they have hundreds of thousands of clients among them.

RMM tools require an agent to be installed on client servers, hypervisors, workstations, networking devices, laptops, and other mobile endpoints, which give them deep access into enterprise networks. "RMM agents/probes normally have OS and below level access," Farajun says. A variety of agents monitor things such as patch and version levels, and hardware performance issues including CPU, memory, fan speeds, and other functions. "These agents/probes are normally not well protected, if at all," Farajun says.

When MSPs use their RMM platform with tightly integrated backup solutions, it provides a single access point for attackers to target dozens, hundreds, or even thousands of organizations, he notes. "One of the best practices is to ensure your most important tools are 'app-gapped,' which means they are not integrated into a common platform, which, if compromised, enables the attackers to use it as a proxy to traverse any other tightly integrated application within a platform," he says.

Image credit: Mr.B-king via Shutterstock

2 of 6
Comment  | 
Print  | 
Comments
Newest First  |  Oldest First  |  Threaded View
robert.cox@gapac.com
50%
50%
[email protected],
User Rank: Apprentice
1/25/2021 | 11:39:59 AM
Any new information or updates?
This story broke a little over a month ago; I'm curious if there are new updates worth reviewing?
Edge-DRsplash-10-edge-articles
I Smell a RAT! New Cybersecurity Threats for the Crypto Industry
David Trepp, Partner, IT Assurance with accounting and advisory firm BPM LLP,  7/9/2021
News
Attacks on Kaseya Servers Led to Ransomware in Less Than 2 Hours
Robert Lemos, Contributing Writer,  7/7/2021
Commentary
It's in the Game (but It Shouldn't Be)
Tal Memran, Cybersecurity Expert, CYE,  7/9/2021
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
The State of Cybersecurity Incident Response
In this report learn how enterprises are building their incident response teams and processes, how they research potential compromises, how they respond to new breaches, and what tools and processes they use to remediate problems and improve their cyber defenses for the future.
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-36239
PUBLISHED: 2021-07-29
Jira Data Center, Jira Core Data Center, Jira Software Data Center from version 6.3.0 before 8.5.16, from 8.6.0 before 8.13.8, from 8.14.0 before 8.17.0 and Jira Service Management Data Center from version 2.0.2 before 4.5.16, from version 4.6.0 before 4.13.8, and from version 4.14.0 before 4.17.0 e...
CVE-2021-37578
PUBLISHED: 2021-07-29
Apache jUDDI uses several classes related to Java's Remote Method Invocation (RMI) which (as an extension to UDDI) provides an alternate transport for accessing UDDI services. RMI uses the default Java serialization mechanism to pass parameters in RMI invocations. A remote attacker can send a malic...
CVE-2021-23416
PUBLISHED: 2021-07-28
This affects all versions of package curly-bracket-parser. When used as a template library, it does not properly sanitize the user input.
CVE-2021-23417
PUBLISHED: 2021-07-28
All versions of package deepmergefn are vulnerable to Prototype Pollution via deepMerge function.
CVE-2021-23415
PUBLISHED: 2021-07-28
This affects the package elFinder.AspNet before 1.1.1. The user-controlled file name is not properly sanitized before it is used to create a file system path.