<?xml version='1.0' encoding='utf-8'?>
<rss version="2.0"><channel><title>Cybersecurity Tracker: SolarWinds Watch</title><link>https://cybersecuritytracker.ai/?stack=1</link><description>Stories and vulnerabilities involving SolarWinds.</description><lastBuildDate>Sun, 26 Jul 2026 22:32:51 GMT</lastBuildDate><item><title>What Changes When Your Software Supply Chain Includes AI Writing Your Code?</title><link>https://thehackernews.com/2026/07/what-changes-when-your-software-supply.html</link><guid isPermaLink="false">cst-519</guid><description>The article discusses how artificial intelligence integration into software development pipelines has introduced new complexity to supply chain security beyond traditional dependency management concerns. It references past incidents like SolarWinds, Log4Shell, and XZ Utils to highlight how software supply chain risks extend beyond visible code components.</description><pubDate>Tue, 07 Jul 2026 11:30:00 GMT</pubDate></item><item><title>March 2026 CVE Landscape: 31 High-Impact Vulnerabilities Identified, Interlock Ransomware Group Exploits Cisco FMC Zero-Day</title><link>https://recordedfuture.com/blog/march-2026-cve-landscape</link><guid isPermaLink="false">cst-1981</guid><description>Insikt Group identified 31 high-impact vulnerabilities actively exploited in March 2026, with 29 rated as very critical. The affected products span major vendors including Cisco, Microsoft, Google, ConnectWise, Citrix, and others, with Microsoft and Apple accounting for approximately 32% of the total. Notable findings include the Interlock ransomware group exploiting a Cisco Firewall Management Center zero-day, the continued exploitation of a nine-year-old Hikvision vulnerability, and public proof-of-concept exploits available for 10 of the 31 vulnerabilities.</description><pubDate>Mon, 13 Apr 2026 00:00:00 GMT</pubDate></item><item><title>The Most Organized Threat Actors Use Your ITSM (BMC FootPrints Pre-Auth Remote Code Execution Chains)</title><link>https://labs.watchtowr.com/thanks-itsms-threat-actors-have-never-been-so-organized-bmc-footprints-pre-auth-remote-code-execution-chains</link><guid isPermaLink="false">cst-563</guid><description>watchTowr Labs discovered four chained vulnerabilities in BMC FootPrints ITSM solution, including authentication bypass, server-side request forgery, and deserialization flaws that enable pre-authenticated remote code execution. The vulnerabilities affect BMC FootPrints versions 20.20.02 through 20.24.01.001, and disclosure to BMC began in June 2025. ITSM solutions like FootPrints are high-value targets because they manage IT inventory, configuration data, and incident information that organized threat actors leverage for ransomware campaigns.</description><pubDate>Wed, 18 Mar 2026 10:02:49 GMT</pubDate></item><item><title>A Threat Actor Abuses Another Free Trial</title><link>https://huntress.com/blog/threat-actor-abuses-elastic-cloud-siem</link><guid isPermaLink="false">cst-741</guid><description>A threat actor exploited SolarWinds Web Help Desk and abused an Elastic Cloud SIEM free trial to exfiltrate data and conduct reconnaissance on targeted infrastructure. The incident demonstrates how attackers leverage legitimate, freely available services to conduct operations while avoiding detection.</description><pubDate>Fri, 06 Mar 2026 21:00:00 GMT</pubDate></item><item><title>Buy A Help Desk, Bundle A Remote Access Solution? (SolarWinds Web Help Desk Pre-Auth RCE Chain(s))</title><link>https://labs.watchtowr.com/buy-a-help-desk-bundle-a-remote-access-solution-solarwinds-web-help-desk-pre-auth-rce-chain-s</link><guid isPermaLink="false">cst-565</guid><description>SolarWinds Web Help Desk has been found to contain multiple pre-authentication remote code execution vulnerabilities via Java deserialization, including CVE-2025-40552, CVE-2025-40553, and CVE-2025-40554. Researchers achieved RCE on a fully patched instance by chaining an authentication bypass with a deserialization flaw, demonstrating that previous patches for similar 2024 vulnerabilities did not fully address the underlying issues. This continues a pattern of recurring deserialization problems in the product.</description><pubDate>Wed, 25 Feb 2026 20:06:32 GMT</pubDate></item><item><title>Active Exploitation of SolarWinds Web Help Desk (CVE-2025-26399)</title><link>https://huntress.com/blog/active-exploitation-solarwinds-web-help-desk-cve-2025-26399</link><guid isPermaLink="false">cst-757</guid><description>Huntress has identified active exploitation of CVE-2025-26399, a deserialization and remote code execution vulnerability affecting SolarWinds Web Help Desk. Attackers are currently leveraging this flaw in production environments.</description><pubDate>Sun, 08 Feb 2026 06:00:00 GMT</pubDate></item><item><title>What Are Hackers Searching for in SolarWinds Serv-U (CVE-2024-28995)?</title><link>https://greynoise.io/blog/what-are-hackers-searching-for-in-solarwinds-serv-u-cve-2024-28995</link><guid isPermaLink="false">cst-1932</guid><description>GreyNoise is tracking exploit attempts targeting CVE-2024-28995 in SolarWinds Serv-U through honeypot monitoring. The research identifies specific files that attackers are targeting and provides real-time visibility into exploitation patterns to help security teams distinguish active threats from background noise.</description><pubDate>Mon, 30 Sep 2024 00:00:00 GMT</pubDate></item><item><title>The SolarWinds Attack</title><link>https://wiz.io/blog/the-solarwinds-attack</link><guid isPermaLink="false">cst-1843</guid><description>The SolarWinds supply chain compromise, discovered in December 2020, involved attackers injecting malicious code into legitimate software updates from the IT management vendor SolarWinds, affecting thousands of organizations including U.S. government agencies. The attack demonstrated how trusted software distribution channels can be weaponized to achieve widespread access and persistence. This incident became a watershed moment for understanding supply chain risk and the need for enhanced software integrity controls.</description><pubDate>Mon, 01 Feb 2021 12:52:22 GMT</pubDate></item><item><title>Supply Chain Exploitation of SolarWinds Orion Software | Huntress</title><link>https://huntress.com/blog/rapid-response-supply-chain-exploitation-of-solarwinds-orion-software</link><guid isPermaLink="false">cst-1214</guid><description>SolarWinds' Orion platform was exploited as part of a coordinated attack to distribute malware through the software supply chain. The attack leveraged the trusted nature of the platform to reach multiple downstream victims. This represents a significant supply chain compromise affecting organizations that rely on the management software.</description><pubDate>Mon, 14 Dec 2020 00:00:00 GMT</pubDate></item><item><title>Validating the SolarWinds N-central 'Dumpster Diver' Vuln | Huntress</title><link>https://huntress.com/blog/validating-the-solarwinds-n-central-dumpster-diver-vulnerability-5e3a045982e5</link><guid isPermaLink="false">cst-1223</guid><description>Huntress has validated a vulnerability in SolarWinds N-central that has been labeled the 'Dumpster Diver' vulnerability. The validation work involved testing and confirming the technical details of this flaw in the platform. SolarWinds N-central is a remote monitoring and management tool used by managed service providers and enterprises.</description><pubDate>Fri, 24 Jan 2020 16:00:00 GMT</pubDate></item></channel></rss>