A letter from Atera's CTO to all customers

muna+prod
muna+prod Member, Administrator, Internal Posts: 25 admin

Hello all,

I’m sharing below the email that our CTO and Co-founder, Oshri Moyal, sent out to all clients earlier this morning. I hope this helps provide clarity on the situation and explains the reason for the short notice.

A Letter from Atera's CTO

Dear customers,

Over the past few days, we’ve asked you to take several security steps at short notice. We recognize that this was challenging and may have felt abrupt, but please know these measures were critical and, as part of Atera’s security policy, could not be postponed.


Why we took immediate action
In recent weeks, we observed an increase in attempts by malicious actors to misuse Atera’s free trial. To keep the trial environment clean, we hardened our installers and coordinated with our digital certificate authority to rotate certificates by August 30. Our sole intent and the urgency of our actions were to ensure that bad actors are locked out, permanently. We want to clarify that the Atera platform, installers, customers, and certificates were not compromised in any way, and that all customer data continues to be completely safe. 

 

Up-to-date status

  • More than 95% of agents expected to upgrade have already done so successfully.
  • Our monitoring confirms that all systems remain secure
    and uncompromised.
  • Agents coming online continue to upgrade automatically in
    the background.
  • For machines that remain outdated after August 30th, leading antivirus vendors have confirmed that by whitelisting Atera, those agents should continue to function without disruption now that Atera has rotated the certificates.

 

Next steps for you
To minimize any potential interruptions, particularly for agents that may remain offline until after August 30th, we recommend taking the following preventive step:

  • Whitelist the Atera agent on your Endpoint Security Platform. You can find detailed instructions in our Knowledge Base article. Our support team is also available to walk you through the configuration and other IT needs.

 

Atera’s commitment to you
Please be assured:

  • We will continue to provide timely updates.
  • Our team is available to answer questions, address concerns, or schedule calls if you’d like to discuss this further.
  • Above all, our focus remains on keeping your systems protected and ensuring that Atera continues to be a secure, reliable platform.

 
I want to personally thank you for your patience, responsiveness, and understanding during the past few days. Your trust, satisfaction, and the security of your environments are our highest priorities. With your support and partnership, we will continue to work to stay ahead of evolving threats, keep bad actors out, and protect the environments that you and your clients depend on.

 

Sincerely,
Oshri Moyal

CTO & Co-founder, Atera 

Comments

  • muna+prod
    muna+prod Member, Administrator, Internal Posts: 25 admin

    Hi there KansasCityTech :)
    Whitelisting local agents is a common practice to make sure legitimate software continues to function properly (not just for RMM tools).
    This has also been an official standard recommendation of Atera from before the incident.
    Whitelisting Atera's processes does not reduce or effect our security level or resiliency.

Topics