© (c) Cyberfreek Industries, llc 1997-2025 All rights reserved.

Various news media for Cyber Security are posting an article that Kaspersky deleted itself and installed a lesser known AntiVirus product, supposedly without any warning nor communication to North America Computer users computers.

This is just one link from : bleepingcomputer  there are tons of others dating back quite a few years.

Supposedly there was an email sent out about this, but may have been blocked because of spam filters.....

As many of us know, Kaspersky has been in the spotlight for many years over many accusations it has been intentionally spying for Russia on users systems that have this installed on.  The US Government has moved to block Kaspersky sales within the continental US.

However, many in the Cyber Security World are upset and red flagging this that Kaspersky has had unmitigated access to peoples computer.  Well wait a second.  The software is loaded low in the stack as are all other AV products, software and even MS Windows OS modules. This is nothing new.  But it brings into focus that these vendors can pretty much do anything they want if they were compromised.  They have the keys to your kingdom via updates and remote upload/download and worse, remote execution of software.  Is this really shocking or is it that Kaspersky doing so, let the cat out of the proverbial bag and now everyone is waking up to the dangers of allowing 3rd party auto updates.  {oooo  shocker}

The Auto update, Auto control is nothing new.  It's been around for many many years.  A 3rd party vendor can download, update/install software all without the user knowing about it.  It's been around for many years. End users want auto updates because they have given up the control to these 3rd party vendors to "do it for them".  Look recently what happened when Crowdstrike did not test their software accurately and pushed out an update through Microsoft.  BOOM!  The whole internet went dark.

So I have to ask you and your IT department, why are we allowing 3rd party auto updates without vetting first?  Many will say it's because no one has the budget to test all updates so they release control over their systems and trust the vendors.  Others will say that "the vendors will not cause disruptions, it damages their reputation, so we are forced to trust them".  Hmm,  trust without verification.  Doesn't that fly in the face of Cyber Security Experts?  Doesn't the Kaspersky and Crowdstrike events make you question certain policies and procedures?  It should.

Not so long ago, people fully trusted Cisco for the supply of Routers, Switches, Firewalls and other gear that Cisco outsourced to China.  Then China began copying the OS and forging "original Cisco Equipment" with broken, back-doored  devices.   Doesn't this also add to the issue of over-trusting vendors and 3rd parties?  Link Here about Ciso devices Back-Doored.  But wait, this has been going on for over 15 years now.  This is nothing new with Cisco Products.    It's the failure of large Core Internet companies to send off their product to 3rd of 4th party countries.  You ask them to sign an NDA, they steal the IOS, reverse engineer it, load it into your products you want them the create for you and  Viola!  You created your own problem, demise and failed your Zero Trust initiative.

When will people in IT realize, you give up your right to vet software updates, you open yourself to who knows what.

Here's food for thought: How about software that is downloaded from a drive by infection that is allowed to be installed on a system without your permission?  I say "without your permission" because Users do it all the time!  Most companies allow Admin Privileges  for anyone on their desktops or laptops supplied by your IT department.  There's one of the top 3 no-no's for IT.  Lock it down. For Need Only.

I have more to say on the Crowdstrike in another article.

Yes, this also brings up OS updates that break applications, software that has been written for a specific libraries and functionalities, fail if libraries or run times are updated.  But wait, aren't Java apps supposed to be agnostic?   THAT is for another article in the near future.

The bottom line is to set up a vetting infrastructure (virtual too) to pretest these "updates" and "patches" internally before you push anything out.  Never trust an update until you can verify it.  Even from the OS vendors.

 

Stay Secure people.