Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

News

12/18/2020
10:40 AM
Jai Vijayan
Jai Vijayan
Slideshows
Connect Directly
Twitter
LinkedIn
RSS
E-Mail

5 Key Takeaways From the SolarWinds Breach

New details continue to emerge each day, and there may be many more lessons to learn from what could be among the largest cyberattacks ever.
2 of 6

Remote Monitoring and Management Tools Are an Attack Vector
The SolarWinds incident shows how remote monitoring and management (RMM) tools present an attractive attack vector, says Eran Farajun, executive vice president at Asgira. Many managed service providers use RMM tools to monitor client networks, endpoints, and devices. SolarWinds has thousands of MSPs as its customers; together, they have hundreds of thousands of clients among them.
RMM tools require an agent to be installed on client servers, hypervisors, workstations, networking devices, laptops, and other mobile endpoints, which give them deep access into enterprise networks. 'RMM agents/probes normally have OS and below level access,' Farajun says. A variety of agents monitor things such as patch and version levels, and hardware performance issues including CPU, memory, fan speeds, and other functions. 'These agents/probes are normally not well protected, if at all,' Farajun says.
When MSPs use their RMM platform with tightly integrated backup solutions, it provides a single access point for attackers to target dozens, hundreds, or even thousands of organizations, he notes. 'One of the best practices is to ensure your most important tools are 'app-gapped,' which means they are not integrated into a common platform, which, if compromised, enables the attackers to use it as a proxy to traverse any other tightly integrated application within a platform,' he says.
Image credit: Mr.B-king via Shutterstock

Remote Monitoring and Management Tools Are an Attack Vector

The SolarWinds incident shows how remote monitoring and management (RMM) tools present an attractive attack vector, says Eran Farajun, executive vice president at Asgira. Many managed service providers use RMM tools to monitor client networks, endpoints, and devices. SolarWinds has thousands of MSPs as its customers; together, they have hundreds of thousands of clients among them.

RMM tools require an agent to be installed on client servers, hypervisors, workstations, networking devices, laptops, and other mobile endpoints, which give them deep access into enterprise networks. "RMM agents/probes normally have OS and below level access," Farajun says. A variety of agents monitor things such as patch and version levels, and hardware performance issues including CPU, memory, fan speeds, and other functions. "These agents/probes are normally not well protected, if at all," Farajun says.

When MSPs use their RMM platform with tightly integrated backup solutions, it provides a single access point for attackers to target dozens, hundreds, or even thousands of organizations, he notes. "One of the best practices is to ensure your most important tools are 'app-gapped,' which means they are not integrated into a common platform, which, if compromised, enables the attackers to use it as a proxy to traverse any other tightly integrated application within a platform," he says.

Image credit: Mr.B-king via Shutterstock

2 of 6
Comment  | 
Print  | 
Comments
Oldest First  |  Newest First  |  Threaded View
robert.cox@gapac.com
50%
50%
[email protected],
User Rank: Apprentice
1/25/2021 | 11:39:59 AM
Any new information or updates?
This story broke a little over a month ago; I'm curious if there are new updates worth reviewing?
Edge-DRsplash-10-edge-articles
I Smell a RAT! New Cybersecurity Threats for the Crypto Industry
David Trepp, Partner, IT Assurance with accounting and advisory firm BPM LLP,  7/9/2021
News
Attacks on Kaseya Servers Led to Ransomware in Less Than 2 Hours
Robert Lemos, Contributing Writer,  7/7/2021
Commentary
It's in the Game (but It Shouldn't Be)
Tal Memran, Cybersecurity Expert, CYE,  7/9/2021
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
The State of Cybersecurity Incident Response
In this report learn how enterprises are building their incident response teams and processes, how they research potential compromises, how they respond to new breaches, and what tools and processes they use to remediate problems and improve their cyber defenses for the future.
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2021-21553
PUBLISHED: 2021-08-03
Dell PowerScale OneFS versions 8.1.0-9.1.0 contain an Incorrect User Management vulnerability.under some specific conditions, this can allow the CompAdmin user to elevate privileges and break out of Compliance mode. This is a critical vulnerability and Dell recommends upgrading at the earliest.
CVE-2021-21562
PUBLISHED: 2021-08-03
Dell EMC PowerScale OneFS contains an untrusted search path vulnerability. This vulnerability allows a user with (ISI_PRIV_LOGIN_SSH or ISI_PRIV_LOGIN_CONSOLE) and (ISI_PRIV_SYS_UPGRADE or ISI_PRIV_AUDIT) to provide an untrusted path which can lead to run resources that are not under the application...
CVE-2021-21563
PUBLISHED: 2021-08-03
Dell EMC PowerScale OneFS versions 8.1.2-9.1.0.x contain an Improper Check for Unusual or Exceptional Conditions in its auditing component.This can lead to an authenticated user with low-privileges to trigger a denial of service event.
CVE-2021-21565
PUBLISHED: 2021-08-03
Dell PowerScale OneFS versions 9.1.0.3 and earlier contain a denial of service vulnerability. SmartConnect had an error condition that may be triggered to loop, using CPU and potentially preventing other SmartConnect DNS responses.
CVE-2021-26085
PUBLISHED: 2021-08-03
Affected versions of Atlassian Confluence Server allow remote attackers to view restricted resources via a Pre-Authorization Arbitrary File Read vulnerability in the /s/ endpoint. The affected versions are before version 7.4.10, and from version 7.5.0 before 7.12.3.