AnyDesk has copped to an IT security "incident" in which criminals broke into the remote-desktop software maker's production systems. The biz has told customers to expect disruption as it attempts to lock down its infrastructure. The application developer, which is said to have more than 170,000 customers worldwide, disclosed the intrusion in a statement on its website late on Friday, claiming it is "not related to ransomware." While there's no specific mention of stolen data, some infosec analysts have pointed out that the disclosure indicates that criminals got hold of AnyDesk's code signing certificate. That would allow miscreants to pass off malware as legit AnyDesk tools to unsuspecting marks. "We have revoked all security-related certificates and systems have been remediated or replaced where necessary," AnyDesk said. "We will be revoking the previous code signing certificate for our binaries shortly and have already started replacing it with a new one. "As a precaution, we are revoking all passwords to our web portal, my.anydesk.com, and we recommend that users change their passwords if the same credentials are used elsewhere." According to infosec world watchers, criminals are selling AnyDesk customer credentials on the dark web, though these may not be related to this latest heist. AnyDesk says it has hired CrowdStrike to assist with remediation and incident response, and notified the authorities. "We can confirm that the situation is under control and it is safe to ...
AnyDesk revokes certs, passwords after IT security breach
The Register
·Jessica Lyons
·Published Feb 5, 2024
·Updated
Affected Software
1 affected component
AnyDesk remote-desktop software
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses a security breach at AnyDesk where criminals accessed their production systems.
2
What security implications are discussed in the article?
The article highlights the potential disruption to services as AnyDesk works to secure its infrastructure following the breach.
3
What products or software are affected?
The affected product is AnyDesk's remote-desktop software.
4
What actions has AnyDesk taken in response to the security incident?
AnyDesk has revoked certificates and passwords to mitigate the impact of the breach.
5
What should customers of AnyDesk anticipate following the security incident?
Customers should expect potential disruptions in service as AnyDesk addresses the security breach.