Honestly, I think this should be the death knell of these "remote monitoring and management" tools that have extreme low-level access to networks and systems, but just like the SolarWinds attack, it feels like these are run by companies with extremely poor security culture. I mean, I'd be willing to trust security to Microsoft or Apple (I mean, at some level, you've got to trust the OS). But giving the keys to the ca…
I used to work for an MSP and we had used Kaseya. There was an AV integration, and then Kaseya changed to Kaspersky. I don’t remember what the prior AV software was. I always thought it bizarre we were actively installing AV software from Russia on banking and medical office PCs.
I viewed it as safer to buy products from anywhere other than someone that has ANY potential at all to go to war with the government of the country I live and work in. I really hope it never happens, but 'cold war' tensions might be waged with little cyber attacks and that software came to mind as a risk.