home.social

#atera — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #atera, aggregated by home.social.

  1. I noticed a (minor but abusable) data leak in the RMM/PSA tool Atera a while ago, reported it and it's now fixed. I think it's somewhat interesting so I wrote it up.

    fyr.io/post/atera-leaked-their

    Tldr: if you tested your SMTP settings, it used a public mailbox on mailinator, allowing anyone to watch for (and respond to, if you're so inclined) mail. Phishing opportunity!

    #infosec #atera #privacy #dataleak #mailinator #writeup #phishing #netsec

  2. The #SophosMDR team also discovered cases where threat actors targeting #PaperCut were abusing the bitsadmin.exe Windows application to download payloads. #BITSAdmin is commonly abused by active adversaries as a "living off the land binary" or #LOLbin, handy for accomplishing the task of downloading payloads.

    The tools exploited in the attacks have included what we refer to as “dual-use agents,” used both legitimately by IT staff and maliciously by attackers. At the time of writing, Sophos has observed the abuse of #AnyDesk, #Atera, #Synchro, #TightVNC, #NetSupport, and #DWAgent remote management tools across multiple campaigns.

    4/6

  3. Atera raises $77M at a $500M valuation to help SMBs manage their remote networks like enterprises do - When it comes to software to help IT manage workers’ devices wherever they happen ... - feedproxy.google.com/~r/Techcr #remotedevicemanagement #remotemonitortech #endpointsecurity #remotemonitoring #smallbusinesses #remoteworking #enterprise #funding #europe #atera #smbs #smes #it