logo

Rackspace monitoring data stolen in ScienceLogic zero-day attack

ID: 93ba6513-f4bd-58cb-a1df-79329e653887

STIX ID: report--93ba6513-f4bd-58cb-a1df-79329e653887

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2024-10-01

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Cloud hosting provider Rackspace experienced a data breach after threat actors exploited a zero-day remote code execution vulnerability in a third-party utility bundled with ScienceLogic SL1, allowing access to internal monitoring webservers and exfiltration of limited customer monitoring data (account names/numbers, usernames, device IDs, IP addresses, and encrypted agent credentials). ScienceLogic developed and distributed a patch and Rackspace rotated credentials and disabled monitoring dashboards; the full scope of affected customers is unknown but the exposed IPs and device metadata could enable follow-on attacks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.