logo

Rackspace Breach Linked to Zero-Day Vulnerability in ScienceLogic SL1’s Third-Party Utility

ID: 71834212-8763-5c11-92c7-215f1e915feb

STIX ID: report--71834212-8763-5c11-92c7-215f1e915feb

Feed Name: Arctic Wolf

Threat Score
50/100

Date Published: 2024-10-04

Date Updated: 2026-07-25

Author: Andres Ramos

...
...

On 24 September 2024 Rackspace disclosed that a threat actor exploited an undocumented remote code execution zero-day in a third-party utility bundled with ScienceLogic SL1, affecting Rackspace Monitoring; ScienceLogic and Rackspace collaborated to patch the issue and notify affected customers. The exposure was limited to performance monitoring data (customer account names/numbers, usernames, Rackspace device IDs/names/IPs and AES256-encrypted internal device agent credentials), no CVE or public exploit is available yet, and Arctic Wolf is monitoring for additional affected products while recommending SL1 updates.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.