home.social

#solarwinds — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #solarwinds, aggregated by home.social.

fetched live
  1. Cl0p Ransomware: Attack Pattern in Threat Intelligence

    A comprehensive analysis of Cl0p ransomware operations spanning six years reveals a sophisticated threat actor with systematic focus on managed file transfer infrastructure. The group has exploited zero-day vulnerabilities in nine distinct campaigns targeting platforms including Accellion FTA, SolarWinds Serv-U, Fortra GoAnywhere, MOVEit Transfer, and Oracle E-Business Suite. Cl0p demonstrates exceptional operational discipline through multi-year reconnaissance, strategic Q4 timing coinciding with holidays, and infrastructure diversification across 79 autonomous systems. The group maintains 10-14 month dormancy periods between campaigns, with pre-attack scanning documented up to two years before exploitation. Their success stems from exploiting a fundamental architectural weakness where internet-facing applications coexist with encryption keys within single trust boundaries, rendering encryption-at-rest controls ineffective.

    Pulse ID: 6a7ca263ee7777102409724c
    Pulse Link: otx.alienvault.com/pulse/6a7ca
    Pulse Author: AlienVault
    Created: 2026-08-12 16:42:11

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Cl0p #CyberSecurity #Encryption #Holiday #InfoSec #OTX #OpenThreatExchange #RAT #RansomWare #Rust #SolarWinds #ZeroDay #bot #AlienVault

  2. Otherworldly #music albums feature #spaceweather data
    Triggered by #solarwinds and lightning, these waves can tell scientists about space. Scientists at the British Antarctic Survey use them to study #space weather and its links to Earth’s climate.
    The radio waves, when converted to sound, make “weird and wonderful noises” that have a melodic quality to them. That inspired him to team up with professional artists to transform the data into music.
    sciencenews.org/article/music-
    archive.ph/5KiWP

  3. CVE-2026-28317 - Critical IDOR in SolarWinds Serv-U leads to privilege escalation. CVSS 9.1. Requires domain admin. Monitor for patch. #CVE #SolarWinds #infosec

    valtersit.com/cve/CVE-2026-283

  4. Contd. [en] Software Supply Chain or Software Politics

    2/2

    "Although no malicious functionality was identified, the case showed how #software #provenance and #governance relationships may create #strategic concerns that are not visible through traditional #technical #analysis." ...

    "#AI systems such as #Mythos may transform how governments identify software vulnerabilities, but vulnerabilities are only part of the strategic picture. The lessons of #XZ, #SolarWinds, and easyjson suggest that some of the most consequential risks may not emerge from #vulnerable code, but from the software ecosystem through which code is governed, trusted, and delivered."

    justsecurity.org/142183/hiding

    #supplychain #vulnerability #go #easyjson #vk #invasion #ukraine #russia

  5. [en] Software Supply Chain or Software Politics

    1/2

    "In 2025, a #software supply chain #vulnerability was discovered in the widely used #Go programming library #easyjson that drew scrutiny due to its association with engineers from the #Russian technology company #VK. The package was hosted on GitHub by a MailRu account, which is owned by VK, and the VK CEO was sanctioned in 2022 by the U.S. Treasury following the Russian #invasion of #Ukraine, due to being or having been a leader or official of the Government of #Russia, amongst other reasons." ...

    ./2

    #supplychain #ai #mythos #xz #solarwinds

  6. Gizmodo: The SolarWinds Hack Was More Humiliating for the Government Than We Thought. “The SolarWinds attack in 2020 was a humiliating all-out assault on U.S. government cybersecurity, and it’s likely that one key reason it’s not more famous is that we still know very little about what the hackers achieved. But we now have a few more crumbs to work with, because new revelations from […]

    https://rbfirehose.com/2026/05/25/gizmodo-the-solarwinds-hack-was-more-humiliating-for-the-government-than-we-thought/
  7. WARNING: A gigantic coronal hole is darkening Uranus! Scientists investigating Uranus have also discovered that it is full of rocks - not just ice. www.livescience.com/space/the-su... #astronomy #nasa #space #earth #sun #solar #moon #science #uranus #sciencesky #solarwinds

    Gigantic 'hole' in the sun wid...

  8. Nachdem es in den letzten Jahren Angriffe auf #Solarwinds oder #Kaseya gab, steht immer stärker auch die #Opensource Community im Fokus von #Cybercrime, indem durch die Kompromittierung einer Maintainer-Identität potenziell Millionen von Entwicklungsumgebungen und CI/CD-Pipelines ebenfalls kompromittiert werden.

    So haben haben Angreifer die #JavaScript-Bibliothek #Axios, eine der meistgenutzten Komponenten moderner Webentwicklung, zeitweise mit #Schadsoftware bestückt:

    it-daily.net/shortnews/npm-bib

  9. On that note, #Windows10 should be forcefully open sourced so that the world can decide wether or not #Micorsoft still gets to screw with the NT kernel and userland - as they are want to do.

    I keep telling people, it's not the flock - but the shepard. Let's not kid ourselves. #SolarWinds is still reeling in my head. "So you spat unverified code into ring 0? Omg".

    The alternative is of course: switch everyone to #Linux, so that #Ableton will port Live and I can leave all this all behind.