Hackers Actively Exploiting SolarWinds Web Help Desk RCE Vulnerability to Deploy Custom Tools
ID: 6e0fcdd1-9988-53c4-afd8-28d1a2d91a0e
STIX ID: report--6e0fcdd1-9988-53c4-afd8-28d1a2d91a0e
Feed Name: cybersecurityNews.com
Active exploitation of a SolarWinds Web Help Desk RCE is being observed: attackers silently install Zoho ManageEngine RMM agents and Velociraptor via hosted MSI payloads, perform Active Directory reconnaissance and lateral movement, disable defenses, establish Cloudflared tunnels, and exfiltrate system data to attacker-controlled Elastic infrastructure; organizations are advised to update WHD to 2026.1+, remove administrative interfaces from the internet, rotate credentials, and hunt for silent MSIs and encoded PowerShell tied to WHD processes.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
