Rackspace monitoring data stolen in ScienceLogic zero-day attack
ID: 93ba6513-f4bd-58cb-a1df-79329e653887
STIX ID: report--93ba6513-f4bd-58cb-a1df-79329e653887
Feed Name: Bleeping Computer
Cloud hosting provider Rackspace experienced a data breach after threat actors exploited a zero-day remote code execution vulnerability in a third-party utility bundled with ScienceLogic SL1, allowing access to internal monitoring webservers and exfiltration of limited customer monitoring data (account names/numbers, usernames, device IDs, IP addresses, and encrypted agent credentials). ScienceLogic developed and distributed a patch and Rackspace rotated credentials and disabled monitoring dashboards; the full scope of affected customers is unknown but the exposed IPs and device metadata could enable follow-on attacks.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
