Supply chain
β Supply Chain
Rackspace Third-Party Breach (October 2024)
Primary Source βIncident Details
Rackspace monitoring data stolen in ScienceLogic zero-day attack. Cloud hosting provider Rackspace suffered a data breach exposing “limited” customer monitoring data after threat actors exploited a zero-day vulnerability in a third-party tool used by the ScienceLogic SL1 platform. ScienceLogic confirmed to BleepingComputer that they quickly developed a patch to address the risk and distributed it to all impacted customers while still providing assistance where needed. “We identified a zero-day remote code execution vulnerability within a non-ScienceLogic third-party utility that is delivered with the SL1 package,” explained a statement from Jessica Lindberg, Vice President at ScienceLogic. Third-party company: ScienceLogic.
Technical Details
- Initial Attack Vector
- Compromise of third-party service provider / vendor relationship
- Vendor / Product
- ScienceLogic
- Supply Chain Attack
- β Confirmed third-party / vendor compromise
Timeline
- 2024-10-01 Breach occurred
- 2024-10-01 Publicly disclosed