home.social

#solarwinds — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #solarwinds, aggregated by home.social.

fetched live
  1. Cl0p Ransomware: Attack Pattern in Threat Intelligence

    A comprehensive analysis of Cl0p ransomware operations spanning six years reveals a sophisticated threat actor with systematic focus on managed file transfer infrastructure. The group has exploited zero-day vulnerabilities in nine distinct campaigns targeting platforms including Accellion FTA, SolarWinds Serv-U, Fortra GoAnywhere, MOVEit Transfer, and Oracle E-Business Suite. Cl0p demonstrates exceptional operational discipline through multi-year reconnaissance, strategic Q4 timing coinciding with holidays, and infrastructure diversification across 79 autonomous systems. The group maintains 10-14 month dormancy periods between campaigns, with pre-attack scanning documented up to two years before exploitation. Their success stems from exploiting a fundamental architectural weakness where internet-facing applications coexist with encryption keys within single trust boundaries, rendering encryption-at-rest controls ineffective.

    Pulse ID: 6a7ca263ee7777102409724c
    Pulse Link: otx.alienvault.com/pulse/6a7ca
    Pulse Author: AlienVault
    Created: 2026-08-12 16:42:11

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Cl0p #CyberSecurity #Encryption #Holiday #InfoSec #OTX #OpenThreatExchange #RAT #RansomWare #Rust #SolarWinds #ZeroDay #bot #AlienVault

  2. Cl0p Ransomware: Attack Pattern in Threat Intelligence

    A comprehensive analysis of Cl0p ransomware operations spanning six years reveals a sophisticated threat actor with systematic focus on managed file transfer infrastructure. The group has exploited zero-day vulnerabilities in nine distinct campaigns targeting platforms including Accellion FTA, SolarWinds Serv-U, Fortra GoAnywhere, MOVEit Transfer, and Oracle E-Business Suite. Cl0p demonstrates exceptional operational discipline through multi-year reconnaissance, strategic Q4 timing coinciding with holidays, and infrastructure diversification across 79 autonomous systems. The group maintains 10-14 month dormancy periods between campaigns, with pre-attack scanning documented up to two years before exploitation. Their success stems from exploiting a fundamental architectural weakness where internet-facing applications coexist with encryption keys within single trust boundaries, rendering encryption-at-rest controls ineffective.

    Pulse ID: 6a7ca263ee7777102409724c
    Pulse Link: otx.alienvault.com/pulse/6a7ca
    Pulse Author: AlienVault
    Created: 2026-08-12 16:42:11

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Cl0p #CyberSecurity #Encryption #Holiday #InfoSec #OTX #OpenThreatExchange #RAT #RansomWare #Rust #SolarWinds #ZeroDay #bot #AlienVault

  3. Cl0p Ransomware: Attack Pattern in Threat Intelligence

    A comprehensive analysis of Cl0p ransomware operations spanning six years reveals a sophisticated threat actor with systematic focus on managed file transfer infrastructure. The group has exploited zero-day vulnerabilities in nine distinct campaigns targeting platforms including Accellion FTA, SolarWinds Serv-U, Fortra GoAnywhere, MOVEit Transfer, and Oracle E-Business Suite. Cl0p demonstrates exceptional operational discipline through multi-year reconnaissance, strategic Q4 timing coinciding with holidays, and infrastructure diversification across 79 autonomous systems. The group maintains 10-14 month dormancy periods between campaigns, with pre-attack scanning documented up to two years before exploitation. Their success stems from exploiting a fundamental architectural weakness where internet-facing applications coexist with encryption keys within single trust boundaries, rendering encryption-at-rest controls ineffective.

    Pulse ID: 6a7ca263ee7777102409724c
    Pulse Link: otx.alienvault.com/pulse/6a7ca
    Pulse Author: AlienVault
    Created: 2026-08-12 16:42:11

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Cl0p #CyberSecurity #Encryption #Holiday #InfoSec #OTX #OpenThreatExchange #RAT #RansomWare #Rust #SolarWinds #ZeroDay #bot #AlienVault

  4. Cl0p Ransomware: Attack Pattern in Threat Intelligence

    A comprehensive analysis of Cl0p ransomware operations spanning six years reveals a sophisticated threat actor with systematic focus on managed file transfer infrastructure. The group has exploited zero-day vulnerabilities in nine distinct campaigns targeting platforms including Accellion FTA, SolarWinds Serv-U, Fortra GoAnywhere, MOVEit Transfer, and Oracle E-Business Suite. Cl0p demonstrates exceptional operational discipline through multi-year reconnaissance, strategic Q4 timing coinciding with holidays, and infrastructure diversification across 79 autonomous systems. The group maintains 10-14 month dormancy periods between campaigns, with pre-attack scanning documented up to two years before exploitation. Their success stems from exploiting a fundamental architectural weakness where internet-facing applications coexist with encryption keys within single trust boundaries, rendering encryption-at-rest controls ineffective.

    Pulse ID: 6a7ca263ee7777102409724c
    Pulse Link: otx.alienvault.com/pulse/6a7ca
    Pulse Author: AlienVault
    Created: 2026-08-12 16:42:11

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Cl0p #CyberSecurity #Encryption #Holiday #InfoSec #OTX #OpenThreatExchange #RAT #RansomWare #Rust #SolarWinds #ZeroDay #bot #AlienVault

  5. Cl0p Ransomware: Attack Pattern in Threat Intelligence

    A comprehensive analysis of Cl0p ransomware operations spanning six years reveals a sophisticated threat actor with systematic focus on managed file transfer infrastructure. The group has exploited zero-day vulnerabilities in nine distinct campaigns targeting platforms including Accellion FTA, SolarWinds Serv-U, Fortra GoAnywhere, MOVEit Transfer, and Oracle E-Business Suite. Cl0p demonstrates exceptional operational discipline through multi-year reconnaissance, strategic Q4 timing coinciding with holidays, and infrastructure diversification across 79 autonomous systems. The group maintains 10-14 month dormancy periods between campaigns, with pre-attack scanning documented up to two years before exploitation. Their success stems from exploiting a fundamental architectural weakness where internet-facing applications coexist with encryption keys within single trust boundaries, rendering encryption-at-rest controls ineffective.

    Pulse ID: 6a7ca263ee7777102409724c
    Pulse Link: otx.alienvault.com/pulse/6a7ca
    Pulse Author: AlienVault
    Created: 2026-08-12 16:42:11

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Cl0p #CyberSecurity #Encryption #Holiday #InfoSec #OTX #OpenThreatExchange #RAT #RansomWare #Rust #SolarWinds #ZeroDay #bot #AlienVault

  6. Otherworldly #music albums feature #spaceweather data
    Triggered by #solarwinds and lightning, these waves can tell scientists about space. Scientists at the British Antarctic Survey use them to study #space weather and its links to Earth’s climate.
    The radio waves, when converted to sound, make “weird and wonderful noises” that have a melodic quality to them. That inspired him to team up with professional artists to transform the data into music.
    sciencenews.org/article/music-
    archive.ph/5KiWP

  7. Otherworldly #music albums feature #spaceweather data
    Triggered by #solarwinds and lightning, these waves can tell scientists about space. Scientists at the British Antarctic Survey use them to study #space weather and its links to Earth’s climate.
    The radio waves, when converted to sound, make “weird and wonderful noises” that have a melodic quality to them. That inspired him to team up with professional artists to transform the data into music.
    sciencenews.org/article/music-
    archive.ph/5KiWP

  8. Otherworldly albums feature data
    Triggered by and lightning, these waves can tell scientists about space. Scientists at the British Antarctic Survey use them to study weather and its links to Earth’s climate.
    The radio waves, when converted to sound, make “weird and wonderful noises” that have a melodic quality to them. That inspired him to team up with professional artists to transform the data into music.
    sciencenews.org/article/music-
    archive.ph/5KiWP

  9. Otherworldly #music albums feature #spaceweather data
    Triggered by #solarwinds and lightning, these waves can tell scientists about space. Scientists at the British Antarctic Survey use them to study #space weather and its links to Earth’s climate.
    The radio waves, when converted to sound, make “weird and wonderful noises” that have a melodic quality to them. That inspired him to team up with professional artists to transform the data into music.
    sciencenews.org/article/music-
    archive.ph/5KiWP

  10. Otherworldly #music albums feature #spaceweather data
    Triggered by #solarwinds and lightning, these waves can tell scientists about space. Scientists at the British Antarctic Survey use them to study #space weather and its links to Earth’s climate.
    The radio waves, when converted to sound, make “weird and wonderful noises” that have a melodic quality to them. That inspired him to team up with professional artists to transform the data into music.
    sciencenews.org/article/music-
    archive.ph/5KiWP

  11. CVE-2026-28317 - Critical IDOR in SolarWinds Serv-U leads to privilege escalation. CVSS 9.1. Requires domain admin. Monitor for patch. #CVE #SolarWinds #infosec

    valtersit.com/cve/CVE-2026-283

  12. CVE-2026-28317 - Critical IDOR in SolarWinds Serv-U leads to privilege escalation. CVSS 9.1. Requires domain admin. Monitor for patch. #CVE #SolarWinds #infosec

    valtersit.com/cve/CVE-2026-283

  13. CVE-2026-28317 - Critical IDOR in SolarWinds Serv-U leads to privilege escalation. CVSS 9.1. Requires domain admin. Monitor for patch. #CVE #SolarWinds #infosec

    valtersit.com/cve/CVE-2026-283

  14. SolarWinds Unlocks Real-Time Performance Visibility for SAP HANA Cloud

    New Data Performance Analyzer (DPA) support brings wait-based analytics and AI-assisted tuning to SAP HANA Cloud, helping DBAs…
    #Germany #DE #Europe #EU #Europa #SAP #databaseadministrators #DPA #sap #SAPHANA #SolarWinds
    europesays.com/germany/51728/

  15. Contd. [en] Software Supply Chain or Software Politics

    2/2

    "Although no malicious functionality was identified, the case showed how #software #provenance and #governance relationships may create #strategic concerns that are not visible through traditional #technical #analysis." ...

    "#AI systems such as #Mythos may transform how governments identify software vulnerabilities, but vulnerabilities are only part of the strategic picture. The lessons of #XZ, #SolarWinds, and easyjson suggest that some of the most consequential risks may not emerge from #vulnerable code, but from the software ecosystem through which code is governed, trusted, and delivered."

    justsecurity.org/142183/hiding

    #supplychain #vulnerability #go #easyjson #vk #invasion #ukraine #russia

  16. Contd. [en] Software Supply Chain or Software Politics

    2/2

    "Although no malicious functionality was identified, the case showed how #software #provenance and #governance relationships may create #strategic concerns that are not visible through traditional #technical #analysis." ...

    "#AI systems such as #Mythos may transform how governments identify software vulnerabilities, but vulnerabilities are only part of the strategic picture. The lessons of #XZ, #SolarWinds, and easyjson suggest that some of the most consequential risks may not emerge from #vulnerable code, but from the software ecosystem through which code is governed, trusted, and delivered."

    justsecurity.org/142183/hiding

    #supplychain #vulnerability #go #easyjson #vk #invasion #ukraine #russia

  17. [en] Software Supply Chain or Software Politics

    1/2

    "In 2025, a #software supply chain #vulnerability was discovered in the widely used #Go programming library #easyjson that drew scrutiny due to its association with engineers from the #Russian technology company #VK. The package was hosted on GitHub by a MailRu account, which is owned by VK, and the VK CEO was sanctioned in 2022 by the U.S. Treasury following the Russian #invasion of #Ukraine, due to being or having been a leader or official of the Government of #Russia, amongst other reasons." ...

    ./2

    #supplychain #ai #mythos #xz #solarwinds

  18. [en] Software Supply Chain or Software Politics

    1/2

    "In 2025, a #software supply chain #vulnerability was discovered in the widely used #Go programming library #easyjson that drew scrutiny due to its association with engineers from the #Russian technology company #VK. The package was hosted on GitHub by a MailRu account, which is owned by VK, and the VK CEO was sanctioned in 2022 by the U.S. Treasury following the Russian #invasion of #Ukraine, due to being or having been a leader or official of the Government of #Russia, amongst other reasons." ...

    ./2

    #supplychain #ai #mythos #xz #solarwinds

  19. [en] Software Supply Chain or Software Politics

    1/2

    "In 2025, a #software supply chain #vulnerability was discovered in the widely used #Go programming library #easyjson that drew scrutiny due to its association with engineers from the #Russian technology company #VK. The package was hosted on GitHub by a MailRu account, which is owned by VK, and the VK CEO was sanctioned in 2022 by the U.S. Treasury following the Russian #invasion of #Ukraine, due to being or having been a leader or official of the Government of #Russia, amongst other reasons." ...

    ./2

    #supplychain #ai #mythos #xz #solarwinds

  20. [en] Software Supply Chain or Software Politics

    1/2

    "In 2025, a #software supply chain #vulnerability was discovered in the widely used #Go programming library #easyjson that drew scrutiny due to its association with engineers from the #Russian technology company #VK. The package was hosted on GitHub by a MailRu account, which is owned by VK, and the VK CEO was sanctioned in 2022 by the U.S. Treasury following the Russian #invasion of #Ukraine, due to being or having been a leader or official of the Government of #Russia, amongst other reasons." ...

    ./2

    #supplychain #ai #mythos #xz #solarwinds

  21. [en] Software Supply Chain or Software Politics

    1/2

    "In 2025, a #software supply chain #vulnerability was discovered in the widely used #Go programming library #easyjson that drew scrutiny due to its association with engineers from the #Russian technology company #VK. The package was hosted on GitHub by a MailRu account, which is owned by VK, and the VK CEO was sanctioned in 2022 by the U.S. Treasury following the Russian #invasion of #Ukraine, due to being or having been a leader or official of the Government of #Russia, amongst other reasons." ...

    ./2

    #supplychain #ai #mythos #xz #solarwinds

  22. “Wie alt bin ich", #kritis Edition

    Weißt du, wo du warst bei
    - #Heartbleed
    - #log4j
    - #gsmr Ausfall 1
    - #gsmr Ausfall 2
    - #WannaCry
    - #solarWinds
    - #NotPetya
    ?

    Zähle deine “Ja”-Antworten und du erfährst dein biologisches Alter:

    (0-1) frische 16
    (2-4) junge 25
    (4-6) bedenkliche 42
    (7) oh oh..

  23. “Wie alt bin ich", #kritis Edition

    Weißt du, wo du warst bei
    - #Heartbleed
    - #log4j
    - #gsmr Ausfall 1
    - #gsmr Ausfall 2
    - #WannaCry
    - #solarWinds
    - #NotPetya
    ?

    Zähle deine “Ja”-Antworten und du erfährst dein biologisches Alter:

    (0-1) frische 16
    (2-4) junge 25
    (4-6) bedenkliche 42
    (7) oh oh..

  24. “Wie alt bin ich", #kritis Edition

    Weißt du, wo du warst bei
    - #Heartbleed
    - #log4j
    - #gsmr Ausfall 1
    - #gsmr Ausfall 2
    - #WannaCry
    - #solarWinds
    - #NotPetya
    ?

    Zähle deine “Ja”-Antworten und du erfährst dein biologisches Alter:

    (0-1) frische 16
    (2-4) junge 25
    (4-6) bedenkliche 42
    (7) oh oh..

  25. “Wie alt bin ich", #kritis Edition

    Weißt du, wo du warst bei
    - #Heartbleed
    - #log4j
    - #gsmr Ausfall 1
    - #gsmr Ausfall 2
    - #WannaCry
    - #solarWinds
    - #NotPetya
    ?

    Zähle deine “Ja”-Antworten und du erfährst dein biologisches Alter:

    (0-1) frische 16
    (2-4) junge 25
    (4-6) bedenkliche 42
    (7) oh oh..

  26. 📰 CISA Mandates Patch for Actively Exploited SolarWinds DoS Flaw Added to KEV Catalog

    📢 CISA KEV ALERT! An actively exploited DoS flaw (CVE-2026-28318) in SolarWinds Serv-U is on the loose. Federal agencies must patch by June 19. All orgs using Serv-U are urged to update immediately! 🚨 #CVE #SolarWinds #Infosec #PatchNow

    🌐 cyber[.]netsecops[.]io

    🔗 cyber.netsecops.io/articles/ci

  27. 📰 CISA Mandates Patch for Actively Exploited SolarWinds DoS Flaw Added to KEV Catalog

    📢 CISA KEV ALERT! An actively exploited DoS flaw (CVE-2026-28318) in SolarWinds Serv-U is on the loose. Federal agencies must patch by June 19. All orgs using Serv-U are urged to update immediately! 🚨 #CVE #SolarWinds #Infosec #PatchNow

    🌐 cyber[.]netsecops[.]io

    🔗 cyber.netsecops.io/articles/ci

  28. 📰 CISA Mandates Patch for Actively Exploited SolarWinds DoS Flaw Added to KEV Catalog

    📢 CISA KEV ALERT! An actively exploited DoS flaw (CVE-2026-28318) in SolarWinds Serv-U is on the loose. Federal agencies must patch by June 19. All orgs using Serv-U are urged to update immediately! 🚨 #CVE #SolarWinds #Infosec #PatchNow

    🌐 cyber[.]netsecops[.]io

    🔗 cyber.netsecops.io/articles/ci

  29. CISA Flags SolarWinds Serv-U Flaw as Actively Exploited

    A critical flaw in SolarWinds Serv-U is being actively exploited, allowing attackers to crash the service with a specially crafted POST request - no authentication required. This denial-of-service vulnerability, tracked as CVE-2026-28318, can be triggered by a simple HTTP POST request with a malicious Content-Encoding header.

    osintsights.com/cisa-flags-sol

    #Solarwinds #Servu #Cve202628318 #DenialOfService #Contentencoding

  30. Hackers Actively Exploit SolarWinds Serv-U Flaw to Crash Servers

    SolarWinds has issued an emergency hotfix to address a critical flaw in its Serv-U file transfer product, which hackers are actively exploiting to crash servers with specially crafted POST requests. A denial-of-service vulnerability, tracked as CVE-2026-28318, can be triggered without authentication, posing a significant threat to…

    osintsights.com/hackers-active

    #Cve202628318 #Solarwinds #Servu #DenialOfService #ManagedFileTransfer

  31. Gizmodo: The SolarWinds Hack Was More Humiliating for the Government Than We Thought. “The SolarWinds attack in 2020 was a humiliating all-out assault on U.S. government cybersecurity, and it’s likely that one key reason it’s not more famous is that we still know very little about what the hackers achieved. But we now have a few more crumbs to work with, because new revelations from […]

    https://rbfirehose.com/2026/05/25/gizmodo-the-solarwinds-hack-was-more-humiliating-for-the-government-than-we-thought/
  32. Gizmodo: The SolarWinds Hack Was More Humiliating for the Government Than We Thought. “The SolarWinds attack in 2020 was a humiliating all-out assault on U.S. government cybersecurity, and it’s likely that one key reason it’s not more famous is that we still know very little about what the hackers achieved. But we now have a few more crumbs to work with, because new revelations from […]

    https://rbfirehose.com/2026/05/25/gizmodo-the-solarwinds-hack-was-more-humiliating-for-the-government-than-we-thought/
  33. Gizmodo: The SolarWinds Hack Was More Humiliating for the Government Than We Thought. “The SolarWinds attack in 2020 was a humiliating all-out assault on U.S. government cybersecurity, and it’s likely that one key reason it’s not more famous is that we still know very little about what the hackers achieved. But we now have a few more crumbs to work with, because new revelations from […]

    https://rbfirehose.com/2026/05/25/gizmodo-the-solarwinds-hack-was-more-humiliating-for-the-government-than-we-thought/
  34. Gizmodo: The SolarWinds Hack Was More Humiliating for the Government Than We Thought. “The SolarWinds attack in 2020 was a humiliating all-out assault on U.S. government cybersecurity, and it’s likely that one key reason it’s not more famous is that we still know very little about what the hackers achieved. But we now have a few more crumbs to work with, because new revelations from […]

    https://rbfirehose.com/2026/05/25/gizmodo-the-solarwinds-hack-was-more-humiliating-for-the-government-than-we-thought/
  35. Gizmodo: The SolarWinds Hack Was More Humiliating for the Government Than We Thought. “The SolarWinds attack in 2020 was a humiliating all-out assault on U.S. government cybersecurity, and it’s likely that one key reason it’s not more famous is that we still know very little about what the hackers achieved. But we now have a few more crumbs to work with, because new revelations from […]

    https://rbfirehose.com/2026/05/25/gizmodo-the-solarwinds-hack-was-more-humiliating-for-the-government-than-we-thought/
  36. WARNING: A gigantic coronal hole is darkening Uranus! Scientists investigating Uranus have also discovered that it is full of rocks - not just ice. www.livescience.com/space/the-su... #astronomy #nasa #space #earth #sun #solar #moon #science #uranus #sciencesky #solarwinds

    Gigantic 'hole' in the sun wid...

  37. WARNING: A gigantic coronal hole is darkening Uranus! Scientists investigating Uranus have also discovered that it is full of rocks - not just ice. www.livescience.com/space/the-su... #astronomy #nasa #space #earth #sun #solar #moon #science #uranus #sciencesky #solarwinds

    Gigantic 'hole' in the sun wid...

  38. WARNING: A gigantic coronal hole is darkening Uranus! Scientists investigating Uranus have also discovered that it is full of rocks - not just ice. www.livescience.com/space/the-su... #astronomy #nasa #space #earth #sun #solar #moon #science #uranus #sciencesky #solarwinds

    Gigantic 'hole' in the sun wid...