Rackspace Breach Linked to Zero-Day Vulnerability in ScienceLogic SL1’s Third-Party Utility
ID: 71834212-8763-5c11-92c7-215f1e915feb
STIX ID: report--71834212-8763-5c11-92c7-215f1e915feb
Feed Name: Arctic Wolf
On 24 September 2024 Rackspace disclosed that a threat actor exploited an undocumented remote code execution zero-day in a third-party utility bundled with ScienceLogic SL1, affecting Rackspace Monitoring; ScienceLogic and Rackspace collaborated to patch the issue and notify affected customers. The exposure was limited to performance monitoring data (customer account names/numbers, usernames, Rackspace device IDs/names/IPs and AES256-encrypted internal device agent credentials), no CVE or public exploit is available yet, and Arctic Wolf is monitoring for additional affected products while recommending SL1 updates.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
