MIT TRACE

MIT CTL Logo
Back to Main Dashboard

BeyondTrust Remote Support compromise forces suspension of affected SaaS instances

In early December 2024, BeyondTrust detected compromise affecting 17 Remote Support SaaS customers. A zero-day vulnerability in a third-party application was used to access a BeyondTrust cloud asset and obtain an infrastructure API key; BeyondTrust revoked the key, suspended and quarantined affected customer instances, and provided alternative Remote Support SaaS instances, producing a direct but contained interruption of its service-delivery environment.

69

Estimated severity

69 / 100

94

Source reliability

94 / 100

Approximate Date

02/12/2024

Targeted Company

BEYONDTRUST

Targeted Company Supply Chain Impact

  1. Distribution & Fulfillment

  2. Procurement & Sourcing

  3. Production & Manufacturing

  4. Sales (Retail & Ecommerce)

  5. Warehousing

  6. Service Delivery

  7. Unrecognized Impact

Supply Chain Relations

No information

Geographic Impact

Country Targeted Company

United States

USA

Other Affected Countries

No other affected countries reported

Target country

United States

Affected countries

United States

Impacted regions

No information

Operational Impact

Duration

No information

Financial impact (USD M)

No information

Impact types

Service unavailabilityOperational disruption

Affected sectors

Technology & IT Services

Affected departments

Information Technology

Attack Profile

Attack types

Zero-day exploitationUnauthorized access

Attributed threat actors

No information

Sources

Please rotate your phone

MIT TRACE is optimized for landscape orientation on mobile.