• Menu
  • Skip to main content
  • Skip to primary sidebar

The Cyber Security News

Latest Cyber Security News

Header Right

  • Latest News
  • Vulnerabilities
  • Cloud Services
government agencies warn of increase in cyberattacks targeting msps

Government Agencies Warn of Increase in Cyberattacks Targeting MSPs

You are here: Home / General Cyber Security News / Government Agencies Warn of Increase in Cyberattacks Targeting MSPs
May 12, 2022

Several cybersecurity authorities from Australia, Canada, New Zealand, the U.K., and the U.S. on Wednesday unveiled a joint advisory warning of threats targeting managed support suppliers (MSPs) and their prospects.

Important among the tips include figuring out and disabling accounts that are no extended in use, enforcing multi-factor authentication (MFA) on MSP accounts that accessibility purchaser environments, and making certain transparency in ownership of security roles and tasks.

MSPs have emerged as an interesting attack route for cybercriminals to scale their attacks, as a vulnerable provider can be weaponized as an initial access vector to breach a number of downstream shoppers at when.

✔ Approved From Our Partners
AOMEI Backupper Lifetime

Protect and backup your data using AOMEI Backupper. AOMEI Backupper takes secure and encrypted backups from your Windows, hard drives or partitions. With AOMEI Backupper you will never be worried about loosing your data anymore.

Get AOMEI Backupper with 72% discount from an authorized distrinutor of AOMEI: SerialCart® (Limited Offer).

➤ Activate Your Coupon Code


The spillover outcomes of these types of intrusions, as witnessed in the wake of higher-profile breaches aimed at SolarWinds and Kaseya in modern many years, have the moment once again underlined the will need to secure the software package source chain.

The targeting of MSPs by destructive cyber actors in an energy to “exploit company-buyer network belief associations” for comply with-on exercise these kinds of as ransomware and cyber espionage against the company as effectively as its customer base, the businesses cautioned.

The major security actions and operational controls outlined in the advisory are as follows –

  • Avoid preliminary compromise by securing internet-experiencing gadgets and utilizing protections from brute-forcing and phishing attacks
  • Enable productive monitoring and logging of units
  • Protected remote accessibility apps and mandate MFA exactly where doable
  • Isolate critical enterprise programs and implement correct network security safeguards
  • Utilize the principle of minimum privilege all over the network atmosphere
  • Deprecate obsolete accounts by way of periodic audits
  • Prioritize security updates for operating programs, programs, and firmware, and
  • Consistently maintain and test offline backups for incident restoration.
  • The Five Eyes notify arrives a 7 days right after the U.S. Nationwide Institute of Criteria and Technology (NIST) revealed up to date cybersecurity steerage for controlling threats in the source chain.

    “MSPs must comprehend their individual supply chain risk and manage the cascading threats it poses to shoppers,” the organizations stated. “Clients ought to recognize the offer chain risk associated with their MSP, such as risk involved with 3rd-party distributors or subcontractors.”

    Located this report interesting? Stick to THN on Facebook, Twitter  and LinkedIn to browse a lot more special content material we submit.


    Some pieces of this post are sourced from:
    thehackernews.com

    Previous Post: «hackers deploy iceapple exploitation framework on hacked ms exchange servers Hackers Deploy IceApple Exploitation Framework on Hacked MS Exchange Servers
    Next Post: Everything We Learned From the LAPSUS$ Attacks everything we learned from the lapsus$ attacks»

    Reader Interactions

    Leave a Reply Cancel reply

    Your email address will not be published. Required fields are marked *

    Primary Sidebar

    Report This Article

    Recent Posts

    • Link Found Connecting Chaos, Onyx and Yashma Ransomware
    • Zoom Patches ‘Zero-Click’ RCE Bug
    • Messages Sent Through Zoom Can Expose People to Cyber-Attack
    • Verizon Report: Ransomware, Human Error Among Top Security Risks
    • How Secrets Lurking in Source Code Lead to Major Breaches
    • Learn How Hackers Can Hijack Your Online Accounts Even Before You Create Them
    • UK Government Cybersecurity Advisory Board Applications Now Open
    • Better together: Accelerating security and success for MSPs with automation
    • GoodWill Ransomware Demands People Help the Most Vulnerable
    • McAfee appoints Greg Johnson as new CEO

    Copyright © TheCyberSecurity.News, All Rights Reserved.