home.social

#solarwinds — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #solarwinds, aggregated by home.social.

  1. SolarWinds Unlocks Real-Time Performance Visibility for SAP HANA Cloud

    New Data Performance Analyzer (DPA) support brings wait-based analytics and AI-assisted tuning to SAP HANA Cloud, helping DBAs…
    #Germany #DE #Europe #EU #Europa #SAP #databaseadministrators #DPA #sap #SAPHANA #SolarWinds
    europesays.com/germany/51728/

  2. Contd. [en] Software Supply Chain or Software Politics

    2/2

    "Although no malicious functionality was identified, the case showed how #software #provenance and #governance relationships may create #strategic concerns that are not visible through traditional #technical #analysis." ...

    "#AI systems such as #Mythos may transform how governments identify software vulnerabilities, but vulnerabilities are only part of the strategic picture. The lessons of #XZ, #SolarWinds, and easyjson suggest that some of the most consequential risks may not emerge from #vulnerable code, but from the software ecosystem through which code is governed, trusted, and delivered."

    justsecurity.org/142183/hiding

    #supplychain #vulnerability #go #easyjson #vk #invasion #ukraine #russia

  3. Contd. [en] Software Supply Chain or Software Politics

    2/2

    "Although no malicious functionality was identified, the case showed how #software #provenance and #governance relationships may create #strategic concerns that are not visible through traditional #technical #analysis." ...

    "#AI systems such as #Mythos may transform how governments identify software vulnerabilities, but vulnerabilities are only part of the strategic picture. The lessons of #XZ, #SolarWinds, and easyjson suggest that some of the most consequential risks may not emerge from #vulnerable code, but from the software ecosystem through which code is governed, trusted, and delivered."

    justsecurity.org/142183/hiding

    #supplychain #vulnerability #go #easyjson #vk #invasion #ukraine #russia

  4. [en] Software Supply Chain or Software Politics

    1/2

    "In 2025, a #software supply chain #vulnerability was discovered in the widely used #Go programming library #easyjson that drew scrutiny due to its association with engineers from the #Russian technology company #VK. The package was hosted on GitHub by a MailRu account, which is owned by VK, and the VK CEO was sanctioned in 2022 by the U.S. Treasury following the Russian #invasion of #Ukraine, due to being or having been a leader or official of the Government of #Russia, amongst other reasons." ...

    ./2

    #supplychain #ai #mythos #xz #solarwinds

  5. [en] Software Supply Chain or Software Politics

    1/2

    "In 2025, a #software supply chain #vulnerability was discovered in the widely used #Go programming library #easyjson that drew scrutiny due to its association with engineers from the #Russian technology company #VK. The package was hosted on GitHub by a MailRu account, which is owned by VK, and the VK CEO was sanctioned in 2022 by the U.S. Treasury following the Russian #invasion of #Ukraine, due to being or having been a leader or official of the Government of #Russia, amongst other reasons." ...

    ./2

    #supplychain #ai #mythos #xz #solarwinds

  6. [en] Software Supply Chain or Software Politics

    1/2

    "In 2025, a #software supply chain #vulnerability was discovered in the widely used #Go programming library #easyjson that drew scrutiny due to its association with engineers from the #Russian technology company #VK. The package was hosted on GitHub by a MailRu account, which is owned by VK, and the VK CEO was sanctioned in 2022 by the U.S. Treasury following the Russian #invasion of #Ukraine, due to being or having been a leader or official of the Government of #Russia, amongst other reasons." ...

    ./2

    #supplychain #ai #mythos #xz #solarwinds

  7. [en] Software Supply Chain or Software Politics

    1/2

    "In 2025, a #software supply chain #vulnerability was discovered in the widely used #Go programming library #easyjson that drew scrutiny due to its association with engineers from the #Russian technology company #VK. The package was hosted on GitHub by a MailRu account, which is owned by VK, and the VK CEO was sanctioned in 2022 by the U.S. Treasury following the Russian #invasion of #Ukraine, due to being or having been a leader or official of the Government of #Russia, amongst other reasons." ...

    ./2

    #supplychain #ai #mythos #xz #solarwinds

  8. [en] Software Supply Chain or Software Politics

    1/2

    "In 2025, a #software supply chain #vulnerability was discovered in the widely used #Go programming library #easyjson that drew scrutiny due to its association with engineers from the #Russian technology company #VK. The package was hosted on GitHub by a MailRu account, which is owned by VK, and the VK CEO was sanctioned in 2022 by the U.S. Treasury following the Russian #invasion of #Ukraine, due to being or having been a leader or official of the Government of #Russia, amongst other reasons." ...

    ./2

    #supplychain #ai #mythos #xz #solarwinds

  9. “Wie alt bin ich", #kritis Edition

    Weißt du, wo du warst bei
    - #Heartbleed
    - #log4j
    - #gsmr Ausfall 1
    - #gsmr Ausfall 2
    - #WannaCry
    - #solarWinds
    - #NotPetya
    ?

    Zähle deine “Ja”-Antworten und du erfährst dein biologisches Alter:

    (0-1) frische 16
    (2-4) junge 25
    (4-6) bedenkliche 42
    (7) oh oh..

  10. “Wie alt bin ich", #kritis Edition

    Weißt du, wo du warst bei
    - #Heartbleed
    - #log4j
    - #gsmr Ausfall 1
    - #gsmr Ausfall 2
    - #WannaCry
    - #solarWinds
    - #NotPetya
    ?

    Zähle deine “Ja”-Antworten und du erfährst dein biologisches Alter:

    (0-1) frische 16
    (2-4) junge 25
    (4-6) bedenkliche 42
    (7) oh oh..

  11. “Wie alt bin ich", #kritis Edition

    Weißt du, wo du warst bei
    - #Heartbleed
    - #log4j
    - #gsmr Ausfall 1
    - #gsmr Ausfall 2
    - #WannaCry
    - #solarWinds
    - #NotPetya
    ?

    Zähle deine “Ja”-Antworten und du erfährst dein biologisches Alter:

    (0-1) frische 16
    (2-4) junge 25
    (4-6) bedenkliche 42
    (7) oh oh..

  12. “Wie alt bin ich", #kritis Edition

    Weißt du, wo du warst bei
    - #Heartbleed
    - #log4j
    - #gsmr Ausfall 1
    - #gsmr Ausfall 2
    - #WannaCry
    - #solarWinds
    - #NotPetya
    ?

    Zähle deine “Ja”-Antworten und du erfährst dein biologisches Alter:

    (0-1) frische 16
    (2-4) junge 25
    (4-6) bedenkliche 42
    (7) oh oh..

  13. 📰 CISA Mandates Patch for Actively Exploited SolarWinds DoS Flaw Added to KEV Catalog

    📢 CISA KEV ALERT! An actively exploited DoS flaw (CVE-2026-28318) in SolarWinds Serv-U is on the loose. Federal agencies must patch by June 19. All orgs using Serv-U are urged to update immediately! 🚨 #CVE #SolarWinds #Infosec #PatchNow

    🌐 cyber[.]netsecops[.]io

    🔗 cyber.netsecops.io/articles/ci

  14. 📰 CISA Mandates Patch for Actively Exploited SolarWinds DoS Flaw Added to KEV Catalog

    📢 CISA KEV ALERT! An actively exploited DoS flaw (CVE-2026-28318) in SolarWinds Serv-U is on the loose. Federal agencies must patch by June 19. All orgs using Serv-U are urged to update immediately! 🚨 #CVE #SolarWinds #Infosec #PatchNow

    🌐 cyber[.]netsecops[.]io

    🔗 cyber.netsecops.io/articles/ci

  15. CISA Flags SolarWinds Serv-U Flaw as Actively Exploited

    A critical flaw in SolarWinds Serv-U is being actively exploited, allowing attackers to crash the service with a specially crafted POST request - no authentication required. This denial-of-service vulnerability, tracked as CVE-2026-28318, can be triggered by a simple HTTP POST request with a malicious Content-Encoding header.

    osintsights.com/cisa-flags-sol

    #Solarwinds #Servu #Cve202628318 #DenialOfService #Contentencoding

  16. Hackers Actively Exploit SolarWinds Serv-U Flaw to Crash Servers

    SolarWinds has issued an emergency hotfix to address a critical flaw in its Serv-U file transfer product, which hackers are actively exploiting to crash servers with specially crafted POST requests. A denial-of-service vulnerability, tracked as CVE-2026-28318, can be triggered without authentication, posing a significant threat to…

    osintsights.com/hackers-active

    #Cve202628318 #Solarwinds #Servu #DenialOfService #ManagedFileTransfer

  17. Gizmodo: The SolarWinds Hack Was More Humiliating for the Government Than We Thought. “The SolarWinds attack in 2020 was a humiliating all-out assault on U.S. government cybersecurity, and it’s likely that one key reason it’s not more famous is that we still know very little about what the hackers achieved. But we now have a few more crumbs to work with, because new revelations from […]

    https://rbfirehose.com/2026/05/25/gizmodo-the-solarwinds-hack-was-more-humiliating-for-the-government-than-we-thought/
  18. Gizmodo: The SolarWinds Hack Was More Humiliating for the Government Than We Thought. “The SolarWinds attack in 2020 was a humiliating all-out assault on U.S. government cybersecurity, and it’s likely that one key reason it’s not more famous is that we still know very little about what the hackers achieved. But we now have a few more crumbs to work with, because new revelations from […]

    https://rbfirehose.com/2026/05/25/gizmodo-the-solarwinds-hack-was-more-humiliating-for-the-government-than-we-thought/
  19. WARNING: A gigantic coronal hole is darkening Uranus! Scientists investigating Uranus have also discovered that it is full of rocks - not just ice. www.livescience.com/space/the-su... #astronomy #nasa #space #earth #sun #solar #moon #science #uranus #sciencesky #solarwinds

    Gigantic 'hole' in the sun wid...

  20. Nachdem es in den letzten Jahren Angriffe auf #Solarwinds oder #Kaseya gab, steht immer stärker auch die #Opensource Community im Fokus von #Cybercrime, indem durch die Kompromittierung einer Maintainer-Identität potenziell Millionen von Entwicklungsumgebungen und CI/CD-Pipelines ebenfalls kompromittiert werden.

    So haben haben Angreifer die #JavaScript-Bibliothek #Axios, eine der meistgenutzten Komponenten moderner Webentwicklung, zeitweise mit #Schadsoftware bestückt:

    it-daily.net/shortnews/npm-bib

  21. Nachdem es in den letzten Jahren Angriffe auf #Solarwinds oder #Kaseya gab, steht immer stärker auch die #Opensource Community im Fokus von #Cybercrime, indem durch die Kompromittierung einer Maintainer-Identität potenziell Millionen von Entwicklungsumgebungen und CI/CD-Pipelines ebenfalls kompromittiert werden.

    So haben haben Angreifer die #JavaScript-Bibliothek #Axios, eine der meistgenutzten Komponenten moderner Webentwicklung, zeitweise mit #Schadsoftware bestückt:

    it-daily.net/shortnews/npm-bib

  22. Nachdem es in den letzten Jahren Angriffe auf #Solarwinds oder #Kaseya gab, steht immer stärker auch die #Opensource Community im Fokus von #Cybercrime, indem durch die Kompromittierung einer Maintainer-Identität potenziell Millionen von Entwicklungsumgebungen und CI/CD-Pipelines ebenfalls kompromittiert werden.

    So haben haben Angreifer die #JavaScript-Bibliothek #Axios, eine der meistgenutzten Komponenten moderner Webentwicklung, zeitweise mit #Schadsoftware bestückt:

    it-daily.net/shortnews/npm-bib

  23. Nachdem es in den letzten Jahren Angriffe auf #Solarwinds oder #Kaseya gab, steht immer stärker auch die #Opensource Community im Fokus von #Cybercrime, indem durch die Kompromittierung einer Maintainer-Identität potenziell Millionen von Entwicklungsumgebungen und CI/CD-Pipelines ebenfalls kompromittiert werden.

    So haben haben Angreifer die #JavaScript-Bibliothek #Axios, eine der meistgenutzten Komponenten moderner Webentwicklung, zeitweise mit #Schadsoftware bestückt:

    it-daily.net/shortnews/npm-bib

  24. Nachdem es in den letzten Jahren Angriffe auf #Solarwinds oder #Kaseya gab, steht immer stärker auch die #Opensource Community im Fokus von #Cybercrime, indem durch die Kompromittierung einer Maintainer-Identität potenziell Millionen von Entwicklungsumgebungen und CI/CD-Pipelines ebenfalls kompromittiert werden.

    So haben haben Angreifer die #JavaScript-Bibliothek #Axios, eine der meistgenutzten Komponenten moderner Webentwicklung, zeitweise mit #Schadsoftware bestückt:

    it-daily.net/shortnews/npm-bib

  25. On that note, #Windows10 should be forcefully open sourced so that the world can decide wether or not #Micorsoft still gets to screw with the NT kernel and userland - as they are want to do.

    I keep telling people, it's not the flock - but the shepard. Let's not kid ourselves. #SolarWinds is still reeling in my head. "So you spat unverified code into ring 0? Omg".

    The alternative is of course: switch everyone to #Linux, so that #Ableton will port Live and I can leave all this all behind.

  26. On that note, #Windows10 should be forcefully open sourced so that the world can decide wether or not #Micorsoft still gets to screw with the NT kernel and userland - as they are want to do.

    I keep telling people, it's not the flock - but the shepard. Let's not kid ourselves. #SolarWinds is still reeling in my head. "So you spat unverified code into ring 0? Omg".

    The alternative is of course: switch everyone to #Linux, so that #Ableton will port Live and I can leave all this all behind.

  27. latest SolarWinds CVEs.. all critical lmao.. patch patch patch!

    CVE-2025-40538 - Improper Privilege Management
    CVE-2025-40539 - Incorrect Type Conversion or Cast
    CVE-2025-40540 - Incorrect Type Conversion or Cast
    CVE-2025-40541 - Incorrect Type Conversion or Cast & Authorization Bypass Through User-Controlled Key

    SolarWinds Serv-U 15.5.3 and prior versions

    hecate.pw/vulnerabilities?sear

    #vulnerability #security #solarwinds

  28. Security Advisory Summary:
    SolarWinds Serv-U 15.5.4 patches four critical vulnerabilities:
    • CVE-2025-40538 – Broken access control → system admin creation + root RCE
    • Two type confusion flaws → root code execution
    • One IDOR vulnerability → elevated execution

    Attack prerequisites:
    High-privileged access required. Exploitation likely via credential compromise or chained privilege escalation.

    Exposure landscape:
    12K+ internet-facing instances observed (Shodan)
    File transfer platforms remain ransomware-favored entry vectors

    Historical context:
    Prior Serv-U CVEs exploited by ransomware groups and state-aligned actors.

    Immediate actions:
    - Patch to 15.5.4
    - Audit privileged accounts
    - Review FTP/SFTP exposure
    - Monitor for anomalous admin creation

    Source: bleepingcomputer.com/news/secu

    Follow us for tactical advisories and vulnerability intelligence.

    Comment with your detection or hardening recommendations.

    #Infosec #SolarWinds #ThreatIntel #CVE2025 #RCE #PrivilegeEscalation #BlueTeam #SecurityEngineering #AttackSurface #ZeroTrust