Rackspace has reported a data breach that exposed "limited" customer monitoring data after threat actors exploited a zero-day vulnerability in a third-party tool associated with the ScienceLogic SL1 platform. ScienceLogic has confirmed that they promptly developed and released a patch to address the vulnerability, ensuring affected customers were supported throughout the process. Jessica Lindberg, Vice President at ScienceLogic, stated, "We identified a zero-day remote code execution vulnerability within a non-ScienceLogic third-party utility that is part of the SL1 package." The breach was initially highlighted by a user on X, linking a Rackspace outage on September 24 to the active exploitation of the ScienceLogic EM7 platform. The unauthorized access allowed threat actors to compromise three internal Rackspace monitoring web servers. The exposed data includes customer account names, usernames, device IDs, device information, IP addresses, and AES256 encrypted internal device agent credentials. Rackspace has rotated these credentials as a precaution, despite their strong encryption, and reassured customers that no further action is required, as the malicious activity has been contained. While the data exposure is limited, the disclosed IP addresses could pose a risk for potential DDoS attacks or further exploitation. The number of affected customers remains unknown. BleepingComputer has reached out to Rackspace for further information but has yet to receive a response. Customers are encouraged to stay alert for any unusual activity.
A large-scale phishing campaign has been identified leveraging RFQ (Request for Quotation) themed emails to distribute credential-stealing malware. Attackers disguise malicious HTM...
Two critical vulnerabilities in Progress ShareFile have been identified that can be chained to achieve pre-authentication remote code execution (RCE). Discovered by watchTowr resea...
The FBI has issued a warning highlighting potential security and privacy risks associated with widely used mobile applications developed by Chinese companies. These applications, a...