Previously on ScienceLogic - the time last year where they threatened legal action during a vulnerability report via MITRE. https://web.archive.org/web/20230816081531/https://www.securifera.com/blog/2023/08/16/sciencelogic-dumpster-fire/
Previously on ScienceLogic - the time last year where they threatened legal action during a vulnerability report via MITRE. https://web.archive.org/web/20230816081531/https://www.securifera.com/blog/2023/08/16/sciencelogic-dumpster-fire/
A CVE has been allocated for the ScienceLogic ‘third party application’ zero day that lead to the Rackspace breach. CVE-2024-9537
Patches have been made available finally.
The articles for it are all behind a paywall on ScienceLogic portal.
The vulnerability description is an “unspecified vulnerability”.
Friday night dump.
I have a fun blog about the ScienceLogic situation due to drop on Monday entitled “ScienceLogic and their security vulnerability cover ups”. #Rackspace #threatintel #ScienceLogic
Does anybody know which third party application within ScienceLogic is the vulnerable one?
ScienceLogic are refusing to disclose, as are Rackspace, so it’s created this ridiculous situation where there’s an actively exploited zero day in the wild where there’s zero information on how to protect and detect.
My Signal address is in my profile.
PSA for ScienceLogic SL1 customers - go to the support portal and download and apply the security hotfix for the product.
They haven't told people to do this and haven't allocated a CVE and locked it behind a support paywall -- but there's an actively exploited zero day in the product they're trying to actively downplay. #Rackspace #threatintel #ScienceLogic
Sciencelogic have published a security update for ScienceLogic SL1 which fixes the zero day vulnerability.. but they’ve put it behind a paywall, haven’t told customers and haven’t issued a CVE. #Rackspace #threatintel #ScienceLogic
Rackspace monitoring data gestolen door sciencelogic zero-day aanval https://www.trendingtech.news/trending-news/2024/10/39938/rackspace-monitoring-data-gestolen-door-sciencelogic-zero-day-aanval #Rackspace #ScienceLogic #zero-day #databreach #cybersecurity #Trending #News #Nieuws